Powered by Zoomin Software. For more details please contactZoomin

Flowmon Application for QRadar User Guide

From dictionary attacks to compromised host

  • Last Updated: May 1, 2026
  • 3 minute read
    • Flowmon Products
    • Flowmon Anomaly Detection System
    • Documentation

This example demonstrates how an attack can spread through your network. You'll learn how to track a host that becomes compromised and then turns into the source of subsequent attacks.

Start by selecting the SSHDICT (SSH dictionary attacks) detection method.

Dashboard with SSHDICT detection method selected
Dashboard with SSHDICT detection method selected

Apply the source IP as a filter to the graph, similar to the first example. The graph clearly shows that this IP address has performed a substantial amount of scanning.

Graph filtered to show scanning activity from a specific IP address
Graph filtered to show scanning activity from a specific IP address

To determine which hosts have been affected, expand the filter by clicking the arrow in the corner, then click Show events.

Filter expansion showing Show events option
Filter expansion showing Show events option

The system displays a list of events with the applied filter (SSHDICT and your selected source IP address). Click an IP address in the Targets column to check whether these targets have initiated suspicious activity themselves. Such behavior could indicate successful dictionary attacks and compromised target hosts.

Event list showing target IP addresses
Event list showing target IP addresses

If you see no events, it's because the SSHDICT filter is still applied. Remove it by clicking the red cross.

Filter with red cross for removal
Filter with red cross for removal

With 34 pages of events now visible, direct analysis becomes impractical. Use the high-level graph view for more efficient analysis.

Event list showing multiple pages of results
Event list showing multiple pages of results

Return to the Dashboard by expanding the filter and clicking Show dashboard.

Filter showing Show dashboard option
Filter showing Show dashboard option

The Dashboard presents all events in an interactive visual format. Notice the suspicious events and numerous direct internet communication (DIRINET) entries.

Dashboard showing various event types including DIRINET
Dashboard showing various event types including DIRINET

Uncheck DIRINET to focus on other events. The green DICTATTACK event in the morning appears particularly suspicious. You can uncheck other detection methods to focus on this one.

Dashboard with DIRINET unchecked
Dashboard with DIRINET unchecked

Dashboard showing only DICTATTACK events
Dashboard showing only DICTATTACK events

Apply the source IP address as a filter to the Events table to examine specific activities from this host.

Option to apply source IP to Events table
Option to apply source IP to Events table

After applying a DICTATTACK filter and the source IP address, we can see one event of an attack with all the details. It is clear that the previous target of an attack has itself become the source of malicious activities.

Detailed view of a DICTATTACK event
Detailed view of a DICTATTACK event

TitleResults for “How to create a CRG?”Also Available inAlert