In ConnectSecure, Event Sets are the predefined events that can trigger alerts in the supported integrations. Categories organize them and can be enabled with a simple checkbox.

Event Sets are hard-coded and can not be modified or removed from the system.


Event Set - Table of Contents


Event Set - Details

You will find the Event Set options listed under the integration details.

Not all supported ones are shown, so check your specific integration for the Event Set and Integration Rules options.

image-20240607-190051.png

You will not see the Event Set options until you have provided the credentials for the selected integration.

image-20250226-141338.png

Events by Category

Event Set categories include:

System Changes, Problems, Solutions, Entra ID Audit, Entra ID Error, AD Audit, Job Failed, and Certificate Expire in 30 Days.

Below is a breakdown of each category and the available 'events' you can monitor for each.

System Changes

Event

Description

New Company Created

A new company is created in the ConnectSecure portal, using local or PSA options.

New Asset Added

A new asset is added to the All Asset section; this can happen when agents are installed or assets are detected by probe scanning.

New Open Port Discovered (Probe Scan)

A new port is discovered on an internal asset during a probe scan; port discovery and scanning are only done by a Probe agent.

New Open Port Discovered (External Scan)

A new open port is discovered during an external scan; it requires

Probe Went Down

The probe agent is offline and can not be reached

Server Agent Went Down

Any agent (probe or lightweight) that is a ‘Server’ identified by its operating system is offline and can not be reached.


Problems

Event

Description

CISA Vulnerabilities Found

Vulnerabilities found that are published by CISA

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Critical Severity Vulnerabilities Found

Vulnerabilities found with a critical severity as found in the CVSS Base Score

High Severity Vulnerabilities Found

Vulnerabilities found with a critical severity as found in the CVSS Base Score

Medium Severity Vulnerabilities Found

Vulnerabilities found with a critical severity as found in the CVSS Base Score

Remote Login Vulnerabilities Found

Problems related to remote login or remote access problems; IE: RDP-NTLM

SMB Vulnerabilities Found

Problems related to the SMB protocol; IE: SMB_Signing

SSL/TLS Vulnerabilities Found

Problems related to SSL/TLS certificates and ciphers; IE: TLSv1.1, Sweet32, SSL_Heartbleed

Unquoted Service Path Found

Windows-based vulnerability for improperly formatted or unquoted file paths when defining the executable path; IE: C:\Program Files\My Service\service.exe

Vulnerabilities Found During External Scan

Vulnerabilities found during an external scan; refer to your External Assets for configuration and results.

Vulnerabilities Found With EPSS Score > 95

Vulnerability is found where the EPSS score is equal to or above 95% exploitability.


Solutions

Entra ID Audit

Entra ID Error

AD Audit

Job Failed

Certificate Expires in 30 Days

Microsoft 365 Assessment


Events Group By Options

When creating an Event Set alert using one of the options above, you can set the ‘Group By’ field to organize the alerts into groups instead of individual alerts. Each category has its own ‘Group By’ options, as shown in the table below.

image-20240607-191449.png

Event Set Category

Group By Options

Filter By Options

System Changes

ASSET, COMPANY

Problems

OS, PRODUCT, ASSET, COMPANY

OS, APPLICATION, NONE

Solutions

PRODUCT, ASSET, COMPANY, FIX, ASSET AND PRODUCT

OS, APPLICATION, NONE

Entra ID Audit

EVENT, COMPANY

Entra ID Error

COMPANY

AD Audit

EVENT, COMPANY, USER

Job Failed

COMPANY

Certificate Expire In 30 Days

ASSET, COMPANY

Microsoft 365 Assessment

COMPANY

image-20241115-191709.png

Example Scenarios

Group By OS vs. Filter By OS:

Group By OS: Groups all entries with the same operating system (e.g., Windows 10, Ubuntu 22.04), providing a summarized view per OS.

Filter By OS: Allows you to select either OS or Application based vulnerabilites

Group By Product vs. Filter By Application:

Group By Product: Group data by product category (e.g., Microsoft Office, Adobe Suite), showing all related applications under each product.

Filter By Application: Displays only records related to a specific application only (e.g., Microsoft Word), regardless of the product it belongs to.


Need Support?

Contact our support team by sending an email to support@connectsecure.com or by visiting our Partner Portal, where you can create, view, and manage your tickets.

https://cybercns.freshdesk.com/en/support/login

image-20240206-144508.png