tencent cloud

Tencent Container Security Service

Release Notes
Product Introduction
Overview
Strengths
Use Cases
Features and Versions
Purchase Guide
Applying for Trial
Purchasing Pro Edition
Purchasing Image Scan
Purchasing Log Analysis
Getting Started
Operation Guide
Security Overview
Asset Management
Vulnerability Detection
Image Risk Management
Cluster Risk Management
Baseline Management
Runtime Security
Advanced Defense
Policy Management
Protection Switch
Alarm Settings
Log Analysis
Hybrid Cloud Installation Guide
Compromised Container Isolation
Log Field Data Parsing
Practical Tutorial
Mirror Vulnerability Scanning and Vulnerability Management
Troubleshooting
Offline Linux Client
Troubleshooting for Cluster Access
API Documentation
History
Introduction
API Category
Making API Requests
Network Security APIs
Cluster Security APIs
Security Compliance APIs
Runtime security - High-risk syscalls
Runtime Security - Reverse Shell APIs
Runtime Security APIs
Alert Settings APIs
Advanced prevention - K8s API abnormal requests
Asset Management APIs
Security Operations - Log Analysis APIs
Runtime Security - Trojan Call APIs
Runtime Security - Container Escape APIs
Image Security APIs
Billing APIs
Data Types
Error Codes
FAQs
TCSS Policy
Privacy Policy
Data Processing And Security Agreement
Contact Us
Glossary
DocumentationTencent Container Security Service

Event List

Focus Mode
Font Size
Last updated: 2024-01-23 15:44:44
This document describes the event list of the reverse shell feature.

Filtering and Refreshing Events

1. Log in to the TCSS console and click Runtime Security > Reverse Shell > Event list on the left sidebar.
2. On the Event list page, click the search box and search for reverse shell events by keyword such as process name or parent process name.


3. On the Event list page, click

on the right of the Operation column to refresh the list of reverse shell events.

Exporting the Event List

On the Event list page, click

to select the target reverse shell event and click

to export it.
Note:
You can click

to select multiple events and click

to batch export them.




Event Status Processing

On the Event list page, you can mark a reverse shell event as processed or ignore or delete it.
Mark as processed: Click

to select the target reverse shell event and click Mark as processed > OK.
Note:
It's recommended to handle the event by following "Solution" in the event details and mark it as processed.
Ignore: Click

to select the target reverse shell event and click Ignore > OK.
Note:
Only the selected events are ignored. Alerts will be triggered when the same events occur again.
Delete: Click

to select the target reverse shell event and click Delete > OK.
Note:
The selected event record will no longer be displayed in the console and cannot be recovered once deleted. Proceed with caution.

Viewing List Details

1. On the Event list page, click

on the left of the Event type to view the event description.


2. On the Event list page, click the Container name/ID or Image name/ID to enter the asset management list.


3. On the Event list page, click View details to pop up the drawer on the right, which displays the event details, process information, parent process information, and event description.


4. On the Event list page, the event status can be Processed, Ignored, or Pending resolved. You can manipulate events in different statuses as follows:
Processed/Allowed: Click Delete and click OK in the pop-up window.
Note:
The event record will no longer be displayed in the console and cannot be recovered once deleted. Proceed with caution.

Pending resolved: Click Process now to mark the event as processed, ignore or delete it, or add it to the allowlist. For detailed directions, see Event Status Processing.
Ignored: Click Unignore or Delete to turn the event into the Pending resolved status or delete it.



Custom List Management

1. On the Event list page, click

to pop up the Custom List Management window.
2. In the pop-up window, select the target type and click OK.



Key fields in the list

1. First occurred: The time when an alert is first triggered by the reverse shell event.
Note:
By default, the system aggregates the same alert events not processed.
2. Last occurred: The time when an alert is last triggered by the aggregated alert events. You can click the sort button on the right to sort the events in the list in chronological or reverse chronological order.
3. Events: Total number of alerts triggered by the reverse shell event within the aggregation period.
4. Status: Processed, Ignored, Pending resolved, or Allowed. You can quickly filter events in the list by status.

Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback