# Report

<iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media" frameborder="0" height="" src="https://player.vimeo.com/video/1071627060?h=50f958c10a&title=0&byline=0&portrait=0&badge=0&autopause=0&player_id=0&app_id=58479" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" title="Report" width=""></iframe>

#### **Event Report**

The Event Report menu can be found in the Report section of the left sidebar.

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/fxHimage.png)

#### **Event Report List**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/HSLimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/HSLimage.png)

<div id="bkmrk-the-event-report-men-1">The **Event Report** menu in the SmartWAN Portal displays a list of generated reports for events.</div><div id="bkmrk-accessible-under-the">Accessible under the "Report" section, it includes filters for selecting a customer, asset, and date range, a search bar for reports by name or ID, and an "Advanced Search" option.</div><div id="bkmrk--3"></div>#### **Event Report Details**

<div id="bkmrk-the%C2%A0event-report-det"><div><div>The **Event Report Detail Screen** in the SmartWAN Portal is displayed when a report is selected from the **Event Report** menu. It provides a comprehensive view of the report, organized into multiple sections accessible via tabs at the top of the screen.</div></div><div>  
</div></div>**Report Sections (Tabs) Table**

<div id="bkmrk-tab-number-section-n"><div class="overflow-x-auto my-2"><table><thead class="border-b border-primary/20"><tr class="border-primary/10"><th class="break-words">Tab Number</th><th class="break-words">Section Name</th><th class="break-words">Description</th></tr></thead><tbody><tr class="border-primary/10"><td class="break-words">I</td><td class="break-words">Overview</td><td class="break-words">Provides a summary of the report, including title, ID, reporter, date, and analysis period.</td></tr><tr class="border-primary/10"><td class="break-words">II</td><td class="break-words">Statistics</td><td class="break-words">Displays statistical data related to the case, such as event counts and asset details.</td></tr><tr class="border-primary/10"><td class="break-words">III</td><td class="break-words">Analysis</td><td class="break-words">Details the analysis of the case, including root cause and impact assessment.</td></tr><tr class="border-primary/10"><td class="break-words">IV</td><td class="break-words">Remediation</td><td class="break-words">Outlines the remediation steps taken to resolve the incident.</td></tr><tr class="border-primary/10"><td class="break-words">V</td><td class="break-words">Conclusion</td><td class="break-words">Summarizes the outcomes and conclusions of the case response.</td></tr><tr class="border-primary/10"><td class="break-words">VI</td><td class="break-words">Recommendations</td><td class="break-words">Offers recommendations to prevent similar cases in the future.</td></tr></tbody></table>

</div></div>##### **I. OverView**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/ehvimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/ehvimage.png)

The **Event Report Detail Screen** under the "Overview" tab (I) includes the following items, each serving a specific purpose:

<div id="bkmrk-report-title%3A-indica">- **Report Title**: Indicates the main subject or focus of the report, providing a clear identifier for the incident or analysis.
- **Report ID**: A unique identifier assigned to the report for tracking and reference purposes within the system.
- **Reported By**: Identifies the user who generated the report, including their contact information for accountability and follow-up.
- **Report Date**: Specifies the date and time when the report was finalized, helping to establish a timeline for the incident response.
- **Analysis Period**: Defines the time range during which the incident was analyzed, providing context for the duration of the event and response efforts.
- **Distribution Target**: Lists the individuals, teams, or roles to whom the report is distributed, ensuring relevant stakeholders are informed.
- **Summary**: Offers a high-level overview of the incident, including key findings, the nature of the threat, and its impact, to provide a quick understanding of the situation.
- **Related Elements**: Presents statistical data in visual form (e.g., pie charts) to show the distribution of events by severity and the types of assets affected, aiding in understanding the scope and impact of the incident.

</div>##### **II. Statistics**

<div id="bkmrk-the-statistics-tab-%28">The **Statistics** tab (II) in the **Event Report Detail Screen** of the SmartWAN Portal provides statistical insights into the incident, helping users understand the severity, urgency, and distribution of related events.</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/Zfvimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/Zfvimage.png)

<p class="callout info">This image displays a partial section of the complete report.</p>

---

**Statistics Report Summary**

<table id="bkmrk-section-purpose-key-"><thead><tr><th>**Section**</th><th>**Purpose**</th><th>**Key Details**</th></tr></thead><tbody><tr><td>**Threat Case Classification**</td><td>Prioritizes security cases based on severity and urgency.</td><td>- **Severity**: Measures threat danger (Low/High).  
- **Urgency**: Measures response time needed (Low/High).  
- **Matrix**: Combines both (e.g., High Severity + High Urgency = Critical).</td></tr><tr><td>**Distribution of Related Events**</td><td>Visualizes how related security events spread across time/systems.</td><td>- Tracks event frequency and patterns.  
- Aids in identifying attack scope and hotspots.</td></tr><tr><td>**List of Related Events**</td><td>Groups events with shared attributes to uncover attack sequences.</td><td>**Grouping Criteria**:  
- **Common Indicators**: Shared IPs, users, devices.  
- **Time Correlation**: Events in close proximity.  
- **Attack Patterns**: Matches MITRE ATT&amp;CK tactics.  
- **Behavior Analysis**: Suspicious chains (e.g., file execution → external connection).  
- **Threat Intelligence**: Matches known IOCs.</td></tr></tbody></table>

---

**Threat Case Classification Matrix**

<table id="bkmrk-severity-%5C-urgency-l"><thead><tr><th>**Severity \\ Urgency**</th><th>**Low Urgency**</th><th>**High Urgency**</th></tr></thead><tbody><tr><td>**Low Severity**</td><td>Minor threat; resolve later.</td><td>Less critical but needs prompt handling.</td></tr><tr><td>**High Severity**</td><td>Serious threat; no immediate action.</td><td>Critical; requires immediate response.</td></tr></tbody></table>

---

**Key Takeaways**

1. **Prioritization**: Clear severity/urgency tiers streamline incident response.
2. **Pattern Analysis**: Distribution and event grouping reveal attack trends.
3. **Correlation**: Multi-criteria linking (time, behavior, IOCs) enhances threat detection.

##### **III. Analysis**

The Analysis tab (III) in the Event Report Detail Screen of the SmartWAN Portal provides in-depth **threat pattern analysis**, **response effectiveness, and correlations between threat factors.**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/btmimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/btmimage.png)

<p class="callout info">This image displays a partial section of the complete report.</p>

**Threat in Similar Case Occurrences and Responses**

<table id="bkmrk-section-purpose-key--1"><thead><tr><th>**Section**</th><th>**Purpose**</th><th>**Key Details**</th></tr></thead><tbody><tr><td>**Threat in Similar Case Occurrences**</td><td>Analyzes the frequency and severity of past security threats over a specified period.</td><td>- Tracks threat patterns (e.g., monthly trends).  
- Visualizes data to identify critical/high-risk periods.</td></tr><tr><td>**Threat in Similar Case Responses**</td><td>Evaluates the effectiveness of organizational responses to past threats.</td><td>- Assesses response strategies (e.g., speed, methods).  
- Identifies areas for improvement.</td></tr></tbody></table>

---

**Threat Factor Correlation Analysis**

<table id="bkmrk-section-purpose-key--2"><thead><tr><th>**Section**</th><th>**Purpose**</th><th>**Key Details**</th></tr></thead><tbody><tr><td>**Threat Level Distribution of Related Factors**</td><td>Maps the severity levels (Critical/High/Moderate/Low) of linked threat factors.</td><td>- Highlights high-risk elements (e.g., IPs, users).  
- Aids in prioritizing response actions.</td></tr><tr><td>**Probability Distribution of Risk Levels**</td><td>Quantifies the likelihood of each risk level occurring among correlated factors.</td><td>- Uses statistical analysis (e.g., "60% Moderate risk").  
- Supports predictive threat assessment.</td></tr></tbody></table>

<p class="callout info">**Correlation Rules**: Time-based or entity-based logic is applied to detect complex attack patterns.</p>

<p class="callout info">**Threat Scores**: Calculated based on severity, context, and threat intelligence to guide decision-making.</p>

##### **IV. Remediation**

Remediation tab (IV) in the Event Report Detail Screen of the SmartWAN Portal provides **threat mitigation actions**, including detection, containment, recovery, and preventive measures for resolved security cases.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/vkuimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/vkuimage.png)

**Remediation Report Section**

<table id="bkmrk-section-purpose-expl"><thead><tr><th>**Section**</th><th>**Purpose**</th><th>**Explanation**</th></tr></thead><tbody><tr><td>**Detection of Malicious Traffic**</td><td>Identify and analyze suspicious network activities</td><td>Uses SIEM/IDS to detect anomalies like port scanning or unusual connections.</td></tr><tr><td>**Multiple Failed Login Attempts**</td><td>Prevent brute-force attacks and unauthorized access</td><td>Monitors repeated login failures, locks accounts, blocks suspicious IPs, and enforces stronger authentication (e.g., MFA).</td></tr><tr><td>**Detection of Abnormal File Access**</td><td>Protect sensitive data from unauthorized access or exfiltration</td><td>Alerts on unusual file access patterns (e.g., mass downloads). Includes user verification and role-based access reviews.</td></tr><tr><td>**Execution of Unauthorized Applications**</td><td>Block potentially harmful software execution</td><td>Detects unapproved apps (e.g., TeamViewer), terminates processes, and enforces app control policies (e.g., allowlisting).</td></tr></tbody></table>

##### **V. Conclusion**

The Conclusion tab (V) in the Event Report Detail Screen of the SmartWAN Portal provides a synthesis of key findings about cases and indicators of attack.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/SjTimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/SjTimage.png)

**Section Overview**

<table id="bkmrk-section-purpose-expl-1" style="width: 100%;"><thead><tr><th style="width: 13.4684%;">**Section**</th><th style="width: 29.4368%;">**Purpose**</th><th style="width: 57.0948%;">**Explanation**</th></tr></thead><tbody><tr><td style="width: 13.4684%;">**Conclusion**</td><td style="width: 29.4368%;">To synthesize key findings about cases.</td><td style="width: 57.0948%;">Provides a high-level analysis of similarities in attack methods (e.g., code reuse, C2 communication) to link incidents to known threat actors or campaigns. Helps analysts identify operational patterns.</td></tr><tr><td style="width: 13.4684%;">**Indicator of Attack**</td><td style="width: 29.4368%;">To map observed tactics to standardized frameworks for threat categorization and response planning.</td><td style="width: 57.0948%;">Aligns attack techniques (e.g., spearphishing, steganography) with MITRE ATT&amp;CK tactics (e.g., T1566.001). Enables defenders to prioritize mitigations based on proven threat models.</td></tr></tbody></table>

##### **VI. Recommendations**

<div id="bkmrk-the-recommendations-">The **Recommendations** tab (VI) is the final section of the **Event Report Detail Screen** in the SmartWAN Portal.</div><div id="bkmrk-this-tab-provides-ac">This tab provides actionable suggestions and best practices to prevent similar incidents in the future. It focuses on improving security measures, addressing vulnerabilities, and enhancing response strategies based on the incident analysis.</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/VQBimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/VQBimage.png)

<p class="callout info">A sample PDF file of the Event Report described in this guide is available for download. You can access the full report, including all sections (Overview, Statistics, Analysis, Remediation, Conclusion, and Recommendations).  
</p>

<p class="callout info">Sample PDF download: [ANRN-00936.pdf](https://appexnetworksadmin.sharepoint.com/:b:/s/AppExKR/EYg4U4vaESBJhCNcILFycwYBMOBfQ211Z2u7zPdEeMeHxQ?e=URy1w2) (APPEX Networks user only)</p>

<div id="bkmrk--14"></div><div id="bkmrk--15"></div>