The Advanced Threat Prevention Operator Dashboard is a subscription-specific
view that delivers a centralized hub for exploit and command-and-control (C2)
threat activity, offering immediate and actionable insights. Interactive widgets
surface critical efficacy metrics—such as unique C2 and exploit counts, blocking
efficacy, and severity distributions—providing an intuitive starting point for
deeper drill-down analysis. By utilizing contextual data on users, devices, and
policies, security teams can detect, investigate, and remediate threats more
efficiently than ever before.
Flexible Data Filtering: Customize the dashboard time range (from the
last 15 minutes up to 45 days, or define a custom range) and apply general
filters to isolate specific datasets.
Interactive Widgets: Interact directly with individual widgets to filter
data, reorder columns, zoom, view raw data, export as CSV, and toggle legends
and labels.
Key Visibility Metrics
The dashboard provides granular visibility into the following areas:
- Security efficacy—High-level metrics tracking unique C2 and exploit
threats detected, applications involved, and the overall efficacy of ATP
in blocking them.
- Exploit analysis—Breakdowns of exploits detected by type (known
versus unknown), exploit categories, and top threats by signature and
cloud detection.
- Severity and action—Visualization of exploit and C2 severity
levels mapped to the enforcement action taken, showing whether high-risk
attempts are being neutralized or just logged.
- C2 geo-location—Geographic attribution of C2 attacker
infrastructure along with the distribution of internal victim hosts and
external C2 destinations.
Operational Use Cases
Leverage the dashboard data to drive the following investigative and operational
initiatives:
- Validate security policy effectiveness—Trace critical and
high-severity exploits directly to enforcement actions taken by your
security policies, confirming that high-risk attempts are being neutralized
rather than just logged. Identify whether attackers are utilizing novel,
never-before-seen techniques—such as command injection—to bypass
defenses.
- Scope a breach with C2 attribution—Geographically attribute
campaigns to specific state-sponsored or criminal infrastructure. Confirm
the targeted nature of an attack by linking internal victim IPs directly to
external C2 nodes, visualizing the connection between compromised hosts and
global attacker infrastructure.
- Differentiate known and unknown threats—See which vulnerability
exploits and spyware are detected through existing ATP signatures versus
those requiring ATP cloud analysis. The separation between known and
unknown detections quantifies the unique value of cloud-based detection
for zero-day and evasive threats that signatures alone would miss.
- Refine security policies with source attribution—Identify
recurring source IPs and target hosts involved in attacks, and view all
applications associated with vulnerability exploits or C2 communication
to determine which application-based policies need tightening.