Insights: Advanced Threat Prevention
Focus
Strata Cloud Manager

Insights: Advanced Threat Prevention

Table of Contents

Insights: Advanced Threat Prevention

The Advanced Threat Prevention Operator Dashboard provides a central view of exploit and command-and-control threat activity with immediate, actionable insights for security teams.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
Each of these licenses include access to Strata Cloud Manager:
The other licenses and prerequisites needed for visibility are:
  • A role that has permission to view the dashboard
  • Advanced Threat Prevention
  • Strata Logging Service
The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
  • Click Strata Cloud ManagerInsightsSecurityAdvanced Threat Prevention to get started.
This image shows a partial view of the dashboard. Additional widgets may be available, and dashboard content is subject to change.

Dashboard Scope and Capabilities

The Advanced Threat Prevention Operator Dashboard is a subscription-specific view that delivers a centralized hub for exploit and command-and-control (C2) threat activity, offering immediate and actionable insights. Interactive widgets surface critical efficacy metrics—such as unique C2 and exploit counts, blocking efficacy, and severity distributions—providing an intuitive starting point for deeper drill-down analysis. By utilizing contextual data on users, devices, and policies, security teams can detect, investigate, and remediate threats more efficiently than ever before.
Flexible Data Filtering: Customize the dashboard time range (from the last 15 minutes up to 45 days, or define a custom range) and apply general filters to isolate specific datasets.
Interactive Widgets: Interact directly with individual widgets to filter data, reorder columns, zoom, view raw data, export as CSV, and toggle legends and labels.
Key Visibility Metrics
The dashboard provides granular visibility into the following areas:
  • Security efficacy—High-level metrics tracking unique C2 and exploit threats detected, applications involved, and the overall efficacy of ATP in blocking them.
  • Exploit analysis—Breakdowns of exploits detected by type (known versus unknown), exploit categories, and top threats by signature and cloud detection.
  • Severity and action—Visualization of exploit and C2 severity levels mapped to the enforcement action taken, showing whether high-risk attempts are being neutralized or just logged.
  • C2 geo-location—Geographic attribution of C2 attacker infrastructure along with the distribution of internal victim hosts and external C2 destinations.
Operational Use Cases
Leverage the dashboard data to drive the following investigative and operational initiatives:
  • Validate security policy effectiveness—Trace critical and high-severity exploits directly to enforcement actions taken by your security policies, confirming that high-risk attempts are being neutralized rather than just logged. Identify whether attackers are utilizing novel, never-before-seen techniques—such as command injection—to bypass defenses.
  • Scope a breach with C2 attribution—Geographically attribute campaigns to specific state-sponsored or criminal infrastructure. Confirm the targeted nature of an attack by linking internal victim IPs directly to external C2 nodes, visualizing the connection between compromised hosts and global attacker infrastructure.
  • Differentiate known and unknown threats—See which vulnerability exploits and spyware are detected through existing ATP signatures versus those requiring ATP cloud analysis. The separation between known and unknown detections quantifies the unique value of cloud-based detection for zero-day and evasive threats that signatures alone would miss.
  • Refine security policies with source attribution—Identify recurring source IPs and target hosts involved in attacks, and view all applications associated with vulnerability exploits or C2 communication to determine which application-based policies need tightening.