Skip to main content

Application Anomaly Alerts

Lacework generates application-based alerts when there are application-related vulnerabilities detected. You can define alert rules to trigger alerts when application-related vulnerabilities are found. See Alert Rules.

Alert List

The following table lists all the application-based alerts.

Alert NameAlert TypeAlert SubcategoryConnection
New applicationNewBinaryTypeApplicationProcess -> Process
Process -> DNS
Process -> IP
Process-> Destination Process
DNS-> Destination Process
IP -> Destination Process
New child launchedNewChildLaunchedApplication
Bad external client DNSNewExternalClientBadDnsApplicationDomain -> Process
Bad external client IP addressNewExternalClientBadIpApplicationIP -> Process
Bad external client IP address connectionNewExternalClientBadIpConnApplicationIP -> Process
IP -> Machine
New external client IP address connectionNewExternalClientConnApplicationIP -> Process
New external client DNSNewExternalClientDnsApplicationDomain -> Process
New external client IP addressNewExternalClientIpApplicationIP -> Process
IP -> Machine
Bad external hostNewExternalServerBadDnsApplicationProcess -> Domain
Bad external server DNS connectionNewExternalServerBadDNSConnApplicationMachine -> Domain
Bad external server host connectionNewExternalServerBadDNSConnApplicationProcess -> Domain
Bad external server IP addressNewExternalServerBadIpApplicationProcess -> IP
Bad external server IP address connectionNewExternalServerBadIPConnApplicationProcess -> IP
Machine -> IP
Outbound connection to new domainNewExternalServerDnsApplicationProcess -> Domain
New outbound connection from application

Note:
Legacy name: New external host server connection
NewExternalServerDNSConnApplicationProcess -> Domain
New external host server connectionNewExternalServerDNSConnApplicationMachine -> Domain
New external hostNewExternalServerIpApplicationProcess -> Domain
Outbound connection to a new external IP addressNewExternalServerIpApplicationProcess -> IP
New external server IP address connectionNewExternalServerIPConnApplicationProcess -> IP
Machine -> IP
New internal connectionNewInternalConnectionApplicationProcess -> Process
Process -> IP
IP -> Process
Machine -> IP
IP -> Machine
Machine -> Machine
New K8s clusterNewK8ClusterApplication
New K8s namespaceNewK8NamespaceApplicationCluster -> Namespace
Namespace -> Pod
New K8s podNewK8PodApplication

Suppress an Alert

Suppressing specific application-related alerts reduces the number of alerts and allows you to focus on the assets that are most important to you. For details, see Suppress Behavior Anomaly Alerts.