Dr.Web ESS Administrator Notifications
Dr.Web Enterprise Security Suite 13.0.1 administrator notifications from one Server and 960 connected Windows stations, as collector-normalized ECS JSON of the published notification variables, not native CEF, syslog or a captured delivery payload. All seven notification classes occur in both modes. Recurring episodes join an Application Control block, an allowed HOSTS edit, quarantine of the blocked copy and a station-identity collision on one station.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/security-drweb-ess/generator.yml \
--id drweb \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| scan-completed | Scan statistics of a clean or infected targeted Scanner run | 38.3% / 38.2% measured share (off / on) | malware |
| application-control-blocked | Application Control blocks an untrusted executable launch | 19.0% / 19.4% measured share (off / on) | process |
| station-authorization-failed | Station authorization failed, often retried | 13.2% / 12.8% measured share (off / on) | authentication |
| preventive-protection-allowed | User allows a PowerShell HOSTS modification in Ask mode | 9.5% / 9.8% measured share (off / on) | process |
| security-threat-detected | Scanner detects a copy and moves it to quarantine | 7.5% / 7.5% measured share (off / on) | malware |
| station-id-duplicate | Station already logged in: a reconnect collides with the station's registered session | 7.1% / 6.9% measured share (off / on) | authentication |
| station-update-error | Critical error of station update, retried by the agent | 5.4% / 5.5% measured share (off / on) | package |
Realism Features
- One Server and 960 existing Windows stations in one primary group. Stations are picked at random with unequal activity weights drawn per run, about ten notifications per station a day on average, with no rotation or schedule, and independent workflows interleave: clean scans, launch blocks with retries, infected scans, user-allowed HOSTS edits, update failures and connection failures with retries and session collisions.
- About 380 notifications an hour around the clock (about 9,100 a day), each hour varying by up to 10%, with no daily cycle. Follow-up notifications (later workflow steps and retries) lag their modeled gap by 10 s in median (32 s at the 90th percentile, at most about 2 minutes), so the shortest launch retries arrive later than modeled.
- A block prevents launch; the separate PowerShell HOSTS edit uses Preventive protection Ask mode and neither reverses a block nor establishes execution. Move to quarantine removes the original copy, each station holds at most four quarantined copies, and deletion 72 hours after receipt is an assumed external administrator task, not a Dr.Web default or an emitted notification.
- @timestamp is UTC Server receipt in whole seconds; block and Preventive MSG.StationTime is 1-24 seconds earlier under a synchronized station-clock assumption. Workflow mix, retry probabilities, gaps, scan counters and delivery delays are synthetic training assumptions, as primary sources give no rates.
- About 400 times a day an ordinary workflow reproduces a contiguous part of the chain with its own timing. Background never completes the chain, and only its last step is withheld: an ordinary duplicate-ID collision that would complete the chain on its station is not reported (about 4 a day, 0.04% of notifications), and nothing else on the station changes. Detection (about 690 a day) and collision (about 640 a day) rates are set by this separability design and far exceed a typical fleet.
- An episode station never has a scan running, a full quarantine or an unfinished ordinary chain part at the episode start, which slightly favours quieter stations: within two hours of an episode its ordinary notifications run at 0.86 of the station's own rate, while ordinary block-to-detection prefixes show 0.86-1.09; activity alone does not single out episode stations.
- 49/54 (90.7%) coverage of published class-specific variable names, not native-byte certification. Notification names, labels, message text, severity, outcomes and file.* enrichment are collector choices; threat labels are published Dr.Web names, while filenames and hashes are synthetic. No native delivery capture, Elastic sample or live parser round trip was established.
- The chain is a training correlation: it does not prove that malware executed, changed HOSTS, cloned an Agent or corrected a password. Inventory IP and hostname on connection reports denote the registered asset, not an observed request source.
Sample Output
{
"@timestamp": "2026-09-26T18:41:25+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"kind": "event",
"module": "drweb",
"dataset": "drweb.ess",
"action": "application-control-blocked",
"category": [
"process"
],
"type": [
"denied"
],
"outcome": "success",
"severity": 5
},
"message": "Application Control prevented launch of C:\\Users\\Public\\Downloads\\invoice.pdf_20260926_183718.exe on WS-IT-112.",
"observer": {
"vendor": "Doctor Web",
"product": "Enterprise Security Suite",
"version": "13.0.1",
"hostname": "drweb-srv-01.example.test",
"ip": [
"10.20.0.10"
]
},
"host": {
"id": "10a56af1-2be3-4381-927f-4d7b1e02c912",
"name": "WS-IT-112",
"hostname": "WS-IT-112",
"ip": [
"10.20.15.132"
]
},
"user": {
"name": "m.makarov"
},
"file": {
"path": "C:\\Users\\Public\\Downloads\\invoice.pdf_20260926_183718.exe",
"name": "invoice.pdf_20260926_183718.exe"
},
"related": {
"hosts": [
"WS-IT-112"
],
"ip": [
"10.20.15.132"
],
"user": [
"m.makarov"
],
"hash": [
"57a04e9de7e32d301ddbf6b93359a45f1c17f24e8a45b5e4d79ed28533e3b221"
]
},
"drweb": {
"ess": {
"notification": "Application Control blocked the process",
"station": {
"id": "10a56af1-2be3-4381-927f-4d7b1e02c912",
"name": "WS-IT-112",
"ip": "10.20.15.132",
"primary_group": "Workstations"
},
"variables": {
"MSG.AppCtlAction": 5,
"MSG.AppCtlType": 1,
"MSG.Path": "C:\\Users\\Public\\Downloads\\invoice.pdf_20260926_183718.exe",
"MSG.Profile": "Default deny executables",
"MSG.Rule": "Block untrusted application",
"MSG.SHA256": "57a04e9de7e32d301ddbf6b93359a45f1c17f24e8a45b5e4d79ed28533e3b221",
"MSG.StationTime": "2026-09-26T18:41:12+00:00",
"MSG.TestMode": 0,
"MSG.User": "m.makarov"
}
}
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Mix recurring episodes with ordinary activity; false emits ordinary activity only |
| anomaly_interval_hours | 24 | Finite interval from 6 to 8760 hours, measured from the previous actual episode start |
| server_name | drweb-srv-01.example.test | Registered Server hostname |
| server_id | 9f0ca284-b95a-4cc8-8338-f253a30ab001 | Server registration UUID in duplicate-station reports |
| server_ip | 10.20.0.10 | Collector inventory context for the Server |
| server_version | 13.0.1 | Metadata for the documented profile; changing it does not establish other-version fidelity |
| station_group | Workstations | Configured primary-group inventory label |
| ecs_version | 8.17.0 | ECS normalization version |
Related Generators
Suricata IDS/IPS
Suricata EVE JSON output — IDS alerts with ET Open signatures, DNS/HTTP/TLS/SSH protocol logs, NetFlow records, and anomaly detections with correlated flow IDs and MITRE ATT&CK mapping.
Palo Alto Threat
Palo Alto PAN-OS Threat logs — IPS vulnerability exploits, antivirus detections, anti-spyware (DNS sinkhole and C2 callback), WildFire cloud verdicts, file type matching, and network scan detection with correlated severity, action, and threat category fields.
Palo Alto URL Filtering
Palo Alto PAN-OS URL Filtering logs — web browsing activity with 65+ URL categories, allow/block/continue/override actions, App-ID application attribution, and content type inspection.