Notebooklet Class - HostNetworkSummary
Host Network Summary Notebooklet class.
Queries and displays information about network connections by a host including:
Summary of network connections
Visualizations of network events
Geolocation of remote IP addresses
Threat Intelligence enrichment of remote IP addresses
Display Sections
Results Class
HostNetworkSummaryResult
Host Network Summary Results.
Attributes
- flows: pd.DataFrameA Dataframe summarizing all network flows to and from a host.
- flow_matrix: LayoutDOMA plot of network traffic volumes from the host.
- flow_whois: pd.DataFrameNetwork flow data to and from the host enriched with WhoIs information about the IP address.
- flow_map: FoliumMapA map showing the location of all remote IP addresses communicating with the host.
- flow_ti: pd.DataFrameNetwork flow data to and from the host enriched with Threat Intelligence results for the IP address.
Methods
Instance Methods
__init__
run
Inherited methods
check_table_exists
check_valid_result_data
attrib
contains data.get_methods
get_pivot_run
get_provider
list_methods
run_nb_func
run_nb_funcs
Other Methods
add_nb_function
all_options
default_options
description
entity_types
get_help
get_settings
import_cell
keywords
list_options
match_terms
search_terms
.name
print_options
result
result [property] Return result of the most recent notebooklet run.
show_help
silent
silent [property] Get the current instance setting for silent running.
<hr>
run
function documentation
Return host network data.
Parameters
- valuestr
Host name
- dataOptional[pd.DataFrame], optional
Optionally pass raw data to use for analysis, by default None
- timespanTimeSpan
Timespan over which operations such as queries will be performed, by default None. This can be a TimeStamp object or another object that has valid start, end, or period attributes. Alternatively you can pass start and end datetime objects.
- optionsOptional[Iterable[str]], optional
List of options to use, by default None A value of None means use default options.
Returns
- HostNetworkSummaryResults
Result object with attributes for each result type.
Raises
- MsticnbMissingParameterError
If required parameters are missing
- MsticnbDataProviderError
If data is not avaliable
Default Options
map: Display a map of remote IP addresses communicating with the host.
ti: Enrich network flow data with Threat Inteligence.
whois: Enrich network flow data with WhoIs information.
Other Options
None