D
DioIPS

Event Tabs

12 Tabs

Specialized tabs for viewing different event categories.

Tab Overview

TabEventsSource
DashboardOverview, status, graphsAll
ProcessProcess/thread create/exitKernel
NetworkTCP, UDP, DNS, ICMP, ARPWFP + NDIS
RegistryKey/value operationsKernel
FileFile operations, PE writesKernel
ImageDLL/EXE loadingKernel
InjectionRemote threads, handlesKernel
HypervisorCross-process writesHypervisor
USBDevice plug/unplugKernel
ETWETW provider eventsUsermode
AlertsIPS rule matchesAll
RulesRule managementN/A

Common Features

All event tabs share these features:

  • Filter bar — Filter events by various criteria
  • Search — Full-text search across event data
  • Column sorting — Click headers to sort
  • Event details — Click row for full details
  • Export — Export current view to CSV
  • Clear — Clear events from view
  • Pause — Pause event streaming
  • Auto-scroll — Toggle auto-scroll to latest

Filtering

Each tab has context-specific filters:

Process Tab

  • • PID filter
  • • Process name
  • • Event type (create/exit)

Network Tab

  • • Protocol (TCP/UDP/DNS)
  • • IP address
  • • Port number
  • • Direction

Registry Tab

  • • Key path
  • • Operation type
  • • Process name

File Tab

  • • File path
  • • PE only toggle
  • • Operation type

Event Details

Click any event row to see full details in a side panel:

  • • All event fields
  • • Timestamp with milliseconds
  • • Related events (same process/connection)
  • • Copy to clipboard
  • • Create rule from event