Skip to content
  • There are no suggestions because the search field is empty.

Hosts View - Anomalies Tab

Hosts View - Anomalies TabHosts View - Anomalies Tab

Note: The information in this topic applies to NetWitness Version 11.3 and later.

The Anomalies panel provides a list of image hooks, suspicious threads, kernel hooks, and registry discrepancies running on the host. To access this tab, select a host from the Hosts view and click the Anomalies tab.

Workflow

netwitness_workflowhosts.png

What do you want to do?

*You can perform this task in the current view.

Related Topics

Quick Look

Below is an example of the Anomalies tab:

anomalies_hosts_view_1344x450.png

Image HooksImage Hooks

Image hooks found in executable image are displayed in the following columns.

Kernel HooksKernel Hooks

Hooks found on kernel objects are displayed in the following columns.

Suspicious ThreadsSuspicious Threads

Threads whose service table was hooked are displayed in the following columns.

Registry DiscrepanciesRegistry Discrepancies

Configuration settings and options on Microsoft Windows operating systems that are stored are displayed in the following columns.