Events map

The Map layout draws your es-python events as a picture: where the untrusted data came from, which files it was read from, and which sinks it reached. This page explains how to read the map, move around it, and drill into any part of it.

The Map layout

On the es-python list, Layout in the toolbar switches between List (the events table) and Map. The map draws every event the current filters select, so every toolbar filter, the time range, the scope and the Advanced search conditions (a run, for example) apply to it just as they do to the list.

The layout is part of the page address and of saved searches, so a link to the map opens the map. Switching back to List reloads the table.

Reading the map

The map has three columns, joined by arrows that run left to right:

Column What it holds
Sources where untrusted data came from: Network, Files, Standard input, Environment, Command line, Marked by hand (make_vuln()), Fuzzer, Foreign code, and Other sources (buffers and internal values)
Files for data read from files, the files it was read from
Sinks reached the operations the data reached, by sink label

Only what your filtered events contain is drawn: with no network events there is no Network source. A file read through an open descriptor that had no path shows as Unnamed file.

The line above the map sums it up, for example 1,204 events from 3 sources reaching 17 sinks, updated 14:02:11.

Nodes

Each box on the map is a node: one source, one file or one sink. The number on a node is how many events pass through it, and its colour is the worst severity among them. Sink nodes also say what kind of operation they are (running a command, a database query, a file write, and so on).

Point at a node to light up every path through it and dim the rest. Click it to drill down.

Arrows

An arrow joins a source to a file or a sink, or a file to a sink. Its colour is the worst severity on that path (see the legend above the map: Critical, High, Medium, Low, Info), and a thicker arrow carries more events. Point at an arrow to light up its path, and click it to drill into just that flow.

Moving around

Drag the map to move it and scroll over it to zoom in or out. The buttons in its corner do the same: - and + zoom, the percentage shows the current zoom, and Fit shows the whole map at once. Scrolling over the map zooms it instead of scrolling the page; scroll anywhere outside it to move the page.

From the keyboard, press Tab to move between nodes (the focused node's paths light up) and Enter or Space to open one.

Drilling down

Clicking a node or an arrow opens a drill-down in place of the map. It shows:

  • a header naming what you picked (a Source, File, Sink or a Flow such as Network -> os system), with its number of events and occurrences and its worst severity; a sink also says what data reaching it was used for,
  • the part of the map that passes through it,
  • the newest events that match it (up to 200), as ordinary event rows.

Click an event to open its detail; right-click it or press ⋮ for the row menu. If more than 200 events match, the heading says Newest 200 of N events; narrow the filters or switch to the List layout to see the rest.

Narrowing further

Clicking a node or arrow inside a drill-down narrows it further. For example, click Network, then a sink in its smaller map: you now see only the network events that reached that sink, not every event at that sink.

Going back

The Back button at the top of a drill-down steps back one click at a time: to the drill-down it narrowed, then to the list you opened it from (if any), then to the whole map. Its label says where it goes, for example Back to the whole map. Escape does the same. The map comes back where you left it, at the same position and zoom.

More than fits: the file and sink lists

A busy account can have thousands of files. To keep the map readable, the Files column shows the 24 most serious files and the Sinks column the 30 most serious sinks (worst severity first, then most events); the rest fold into one +N more files (or sinks) node at the bottom of the column.

Clicking a +N more node opens a list instead of the map. The All files (N) button above the map opens the same list at any time, whether or not the column folded.

The list shows every file (or, with the Sinks button, every sink) on the map, worst first, with its number of events. Type in Filter by path (or Filter by sink) to search. It shows 300 rows at a time and adds more as you scroll, or with Show more. Click a row to drill down into it; Back from that drill-down returns to the list. Opened from inside a drill-down, the list covers only that drill-down.

Refresh

The map updates itself about every 20 seconds while the Events page is Live. On a very large account, where building the map takes longer, it refreshes less often, and the line above the map says how often (for example auto-refresh every 4 min). It does not refresh while you have an event open or the row menu showing.

Refresh reloads the map immediately. Changing any filter redraws it at once.

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo