Skip to main content

User Anomaly Alerts

Lacework generates user-based alerts when there are user-related vulnerabilities detected. You can define alert rules to trigger alerts when user-related vulnerabilities are found. See Alert Rules.

Alert List

The following table lists all the user-based alerts.

Alert NameAlert TypeAlert SubcategoryConnection
New child launched from vulnerable applicationNewChildLaunchedFromVulnParentUser
Bad external server DNS connectionNewExternalServerBadDNSConnUserMachine -> Domain
Bad external server host connectionNewExternalServerBadDNSConnUserProcess -> Domain
Bad external server IP address connectionNewExternalServerBadIPConnUserProcess -> IP
Machine -> IP
Bad external server IP address connection from vulnerable applicationNewExternalServerBadIPConnFromVulnUser
New outbound connection from applicationNewExternalServerDNSConnUserProcess -> Domain
New external host server connectionNewExternalServerDNSConnUserMachine -> Domain
New external server IP address connectionNewExternalServerIPConnUserProcess -> IP
Machine -> IP
New internal connectionNewInternalConnectionUserProcess -> Process
Process -> IP
IP -> Process
Machine -> IP
IP -> Machine
Machine -> Machine
New privilege escalationNewPrivilegeEscalationUser
New userNewUserUser
New vulnerable internal connectionNewVulnInternalConnectionUserProcess -> Process
Process -> IP
IP -> Process
User launched new binaryUserLaunchedNewBinaryUser
User launched new vulnerable binaryUserLaunchedNewVulnBinaryUser
User logged in from new locationUserLoggedInFromNewLocationUser

Suppress an Alert

Suppressing specific user-related alerts reduces the number of alerts and allows you to focus on the assets that are most important to you. For details, see Suppress Behavior Anomaly Alerts.