
134
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
Figure 5-3
Activity Pane
iTRAC Activities can be used in iTRAC templates to define a workflow step, or they can be
manually executed from within an Incident. Sentinel provides three types of actions that can be used
to build Activities:
Incident Command Activity
Incident Internal Activity
Incident Composite Activity
5.7.1 Incident Command Activity
An Incident Command Activity enables you to launch a specific command with or without
arguments. The following fields from the incident associated with the workflow process can be used
as input to the command:
NOTE:
The command (or a batch file or script that refers to the command) must be stored in the
%ESEC_HOME%\config\exec or $ESEC_HOME/config/exec directory on the iTRAC workflow
server, usually the same machine where the Data Access Server (DAS) is installed.
5.7.2 Incident Internal Activity
An Incident Internal Activity enables you to mail and/or attach information from the Sentinel
database to the incident associated with the workflow process. Each of these options has a
prerequisite:
Vulnerability for the Initiator IP address (SIP) or the Target IP address (DIP):
This
requires that you run a vulnerability scanner and bring the results of the scan into Sentinel using
a Vulnerability (or “information”) Collector
Advisor attack-related data:
This requires the purchase and installation of the optional
Advisor data subscription service.
Asset data:
This requires that you run an asset management tool such as NMAP and bring the
results into Sentinel using an Asset Collector.
DIP [Target IP]
DIP : Port
RT1 (DeviceAttackName)
SIP [Initiator IP]
SIP : Port
Text (incident information in name value pair
format)
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...