Select the Network traffic events section in the application web interface window.
Go to the Observables tab.
In the table, select the object for which you want to view information.
This opens a window containing information about the object.
The window contains the following information:
ID is the unique ID of the object.
Protocol is the protocol used to transfer the object.
File name is the name of the requested file.
URL is the URL from which the file was requested.
The maximum displayed number of characters is 256.
MD5 hash is the MD5 hash of the file.
SHA256 hash is the SHA256 hash of the file.
Detection represents the file scan results in Kaspersky Anti Targeted Attack Platform. It can have the following values: Detected (identified as malicious), Not detected (identified as safe), Excluded (added to exclusions from scanning by the user or excluded from scanning by the system based on the following criteria: file size less than 100 KB and/or HTML format).
URL reputation is information about the reputation of the URL in the KSN database. Possible values: Trusted, Untrusted.
Date and time of detection is the time when the object was detected in network traffic.
Source are the name, IP address, and port of the computer from which the object was sent.
Destination are the name, IP address, and port of the computer to which the object was sent.