Event detail

Clicking an event opens it in place and shows the full story: what happened, why it matters, what to do, and the evidence behind it. This page goes through every block you can see there.

Opening an event

Click a row to open it; click it again to close it. Only one row is open at a time, so opening another closes the first. The detail loads when you open the row, so it can show Loading... for a moment.

Blocks only appear when the event has something to put in them. An event from an older agent, or from a machine with some reporting turned off, simply shows fewer blocks. The sections below follow the order you see on an es-python event; es-chromium adds blocks of its own.

What this means

The first block explains the event in plain words, under a Severity badge that matches the row. It has three parts: What happened, Why this is risky and What to do. Read it first; everything below it is the evidence.

What happened, and the sink label

What happened is one sentence naming where the data came from and what the program did with it. On es-python it starts with the Python call that ran, so you can search your code for it, for example "os.system(): Data that came in over the network was used to run a command on the operating system."

The short label on the row (for example os system) is the event's sink label. When several calls share one check (for example path traversal), the sentence lists all of them, because the event does not say which one ran.

The flow picture

Under the sentence, a small diagram shows the flow: a Source circle (where the data came from, with the file name when it was a file), an arrow for the Tainted value, and a Sink circle naming the call. If the value passed through a sanitizing call on the way, the arrow says "via" and names it. The arrow and sink take the event's severity colour.

Why this is risky: the impact sentence

Why this is risky says who could exploit the flow and what they would gain. On es-python it is one sentence of the form "An attacker who can reach this source may use this kind of flaw to do this", for example "An attacker who can send data to this program over the network may use this command injection to run operating-system commands on the machine, as the user this program runs as."

When the source is trusted (a file only its owner can write, the program's own command line, a fuzzing harness), the sentence says so and explains why the event is rated low or Info. When the value provably did not get through (for example it reached the database as a query parameter), it says what the attacker cannot do.

What to do

What to do is the concrete next step: the safe API to use, the check to add, or "Nothing to change" when the flow is harmless. For a file that other users can write, it tells you to tighten the file's permissions as well as fix the code.

Findings that are not a flow

Some es-chromium findings are about a setting rather than data moving (a missing security header, for example). Their block reads What we found, Why this matters and What to do instead, and has no flow picture.

Command line

The Command line block (es-python) shows how the program that produced the event was started, for example es-python app.py --port 8080, with how many of the event's occurrences came from it and when it last did. One event collects every program that reached the same finding, so the heading can read Command lines (3 runs) and list several.

It appears only when the machine sends command lines (see Sent with each event). Values that look like passwords, tokens or keys are replaced with [masked].

Each entry has up to two buttons:

  • Only this run narrows the list to the one program invocation it came from. It is missing for events from agents that do not report run ids.
  • All runs of this command narrows the list to every invocation with exactly this command line.

Both work by setting a condition in Advanced search; see Runs.

Environment

When the machine also sends its environment, each command line has an Environment (N variables) section underneath. Click it to expand the program's environment variables. Values that look like secrets are shown as [masked]. See Sent with each event.

Source code and Sink code

The Source code block (es-python) is a short listing of your program's own source around the line where the untrusted data first entered, and Sink code is the same around the line that used it. Each names the file and line above the listing, and the line itself is highlighted.

Both appear only when the machine is set to send code (see Sent with each event), and never for events reported before that was turned on.

Repr created and Repr found

A repr is a text representation of the untrusted value. Repr found is the value as it was when it reached the sink, and Repr created is the value as it was when it was first marked untrusted, when EyalSec recorded it. Comparing the two shows how the program changed the data on the way.

On es-chromium these are called Value at the sink (with the untrusted part highlighted) and Data flow, and a separate Tainted payload block shows only the untrusted characters.

Written to

For an event that is a file write (es-python), the Written to block shows the destination path and a badge saying whether other users on the machine can read it: Readable by other users, Owner only or Readability not recorded. Destination file details expands the file's metadata. This is what the severity of a write is based on.

File, Regex or Detail

Some events carry one more line that pins them down: the file path for a file operation (File), the regular expression for a regex operation (Regex), or another detail (Detail). It is also part of what makes two events different events.

Stack trace

The Stack trace is the chain of function calls that were running when the event happened, innermost call last, with file names and line numbers. It tells you which code path led to the sink. On a repeated event it is the trace of the most recent occurrence, unless Unique event keeps each trace as its own event.

Origin

The Origin block describes where the untrusted data came from. For a file it shows the file's type, permissions, whether other users can write it, size, owner and last modification time; More details expands the rest of the file's metadata (inode, links, device and so on), and Show raw shows the origin exactly as the agent sent it. For network data it shows the connection.

Whether other users can write the file matters: data from a file only its owner can write is rated low, while the same flow from a file anyone can write can be serious.

Extension

On es-chromium, the Extension block names the browser extension whose code produced the finding, with its version and its extension id underneath. The same name appears as a small tag on the row, so you can tell findings caused by an installed extension from findings in the page itself.

EyalSec learns the name from the extension itself the first time it runs in a monitored browser. Until then the row shows the extension id, which is what identifies it in the Chrome Web Store.

es-chromium blocks

Both products show What this means, Stack trace and Origin. es-chromium adds these blocks:

Block What it shows
URL, Page The address an attacker must control (the request whose response carried the data, or the page), and the page it landed on
Script, Element The script and position that made the call, and the page element involved
Browser Which monitored browser reported it
Sanitization Why the event was or was not treated as safe (see Suppressed events)

See es-chromium for the details.

Acting on an event

To label an event, write a note, or turn it into a rule that hides it, use the row menu. To see only events like this one, see Filtering.

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo