Advanced IP Defense in Activity Insights
Use the Activity Insights: Threats dashboard in Strata Cloud Manager to visualize Advanced IP Defense threat trends, categories, and severity breakdowns.
| Where Can I Use This? | What Do I Need? |
|
|
- Advanced IP Defense license
- Log forwarding to Strata Logging Service configured
|
The
Activity Insights: Threats dashboard in
Strata Cloud Manager provides a holistic view of threat activity across your NGFW and VM-Series environments.
Advanced IP Defense is integrated as a security subscription alongside
Advanced Threat Prevention,
Advanced DNS Security,
Advanced WildFire, and
Advanced URL Filtering, giving you a unified view of all threat activity in a single pane.
To view Advanced IP Defense detections, select in Strata Cloud Manager. Use the Threat License filter and select Advanced IP Defense to isolate Advanced IP Defense-specific threat data.
Threat License filter — selecting Advanced IP Defense
Threat Chart
The threat chart displays Advanced IP Defense detections as a flow diagram organized by threat category, with severity breakdown on the right. Categories include:
- Reconnaissance & Pre-Attack
- Malware
- Exploitation and Code Execution
- C2 & Exfiltration
- Disruption & Extortion
- Network Protocol Abuse
- Adversary Infrastructure
These threat categories are a shared taxonomy used across all security subscriptions in Activity Insights. They do not map one-to-one with the Advanced IP Defense profile categories (Anonymizers, Association, Abuse, Malware-C2, High-Risk, Direct-to-IP, and Vulnerable) that you configure in policy rules.
The right panel shows total blocked threats and a severity breakdown (Critical, High, Medium, Low, Informational).
Threat chart with severity breakdown
Category Drilldown
Select a category to expand into its subcategories. You can also use the Category & Subcategory filter to jump directly to a subcategory. For example, expanding Exploitation and Code Execution shows subcategories such as Vulnerable IP, Compromised Device, Compromised Server, Exposed Device, Exposed Web Service, Exposed Network Service, Exploit Scanning, Brute Forcing Webapp, Brute Forcing, and In Shellcode.
Category drilldown — Exploitation and Code Execution subcategories
Unique Threats Table
Below the chart, the Unique Threats table lists individual threat entries with columns for Severity, Threat Name, Total by Actions, Users, Applications, Devices, Category, Sub Category, License, Threat ID, and Rule Name.
Unique Threats table
The table entries are interactive:
- Threat Name—Click the threat name to open a Threat Search filtered by the associated IP address.
- Threat ID—Click the Threat ID to open a Threat Search filtered by that ID.
- Users—Click the Users count to open a panel showing the usernames associated with the threat and their activity details.
Users panel — usernames associated with a threat
Selecting a user opens a detailed activity view showing total threats, threats by risk level, and a Unique Threats table scoped to that user.
User activity detail