Hub
Security

Dr.Web ESS Administrator Notifications

Dr.Web Enterprise Security Suite 13.0.1 administrator notifications from one Server and 960 connected Windows stations, as collector-normalized ECS JSON of the published notification variables, not native CEF, syslog or a captured delivery payload. All seven notification classes occur in both modes. Recurring episodes join an Application Control block, an allowed HOSTS edit, quarantine of the blocked copy and a station-identity collision on one station.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/security-drweb-ess/generator.yml \
  --id drweb \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
scan-completedScan statistics of a clean or infected targeted Scanner run38.3% / 38.2% measured share (off / on)malware
application-control-blockedApplication Control blocks an untrusted executable launch19.0% / 19.4% measured share (off / on)process
station-authorization-failedStation authorization failed, often retried13.2% / 12.8% measured share (off / on)authentication
preventive-protection-allowedUser allows a PowerShell HOSTS modification in Ask mode9.5% / 9.8% measured share (off / on)process
security-threat-detectedScanner detects a copy and moves it to quarantine7.5% / 7.5% measured share (off / on)malware
station-id-duplicateStation already logged in: a reconnect collides with the station's registered session7.1% / 6.9% measured share (off / on)authentication
station-update-errorCritical error of station update, retried by the agent5.4% / 5.5% measured share (off / on)package

Realism Features

  • One Server and 960 existing Windows stations in one primary group. Stations are picked at random with unequal activity weights drawn per run, about ten notifications per station a day on average, with no rotation or schedule, and independent workflows interleave: clean scans, launch blocks with retries, infected scans, user-allowed HOSTS edits, update failures and connection failures with retries and session collisions.
  • About 380 notifications an hour around the clock (about 9,100 a day), each hour varying by up to 10%, with no daily cycle. Follow-up notifications (later workflow steps and retries) lag their modeled gap by 10 s in median (32 s at the 90th percentile, at most about 2 minutes), so the shortest launch retries arrive later than modeled.
  • A block prevents launch; the separate PowerShell HOSTS edit uses Preventive protection Ask mode and neither reverses a block nor establishes execution. Move to quarantine removes the original copy, each station holds at most four quarantined copies, and deletion 72 hours after receipt is an assumed external administrator task, not a Dr.Web default or an emitted notification.
  • @timestamp is UTC Server receipt in whole seconds; block and Preventive MSG.StationTime is 1-24 seconds earlier under a synchronized station-clock assumption. Workflow mix, retry probabilities, gaps, scan counters and delivery delays are synthetic training assumptions, as primary sources give no rates.
  • About 400 times a day an ordinary workflow reproduces a contiguous part of the chain with its own timing. Background never completes the chain, and only its last step is withheld: an ordinary duplicate-ID collision that would complete the chain on its station is not reported (about 4 a day, 0.04% of notifications), and nothing else on the station changes. Detection (about 690 a day) and collision (about 640 a day) rates are set by this separability design and far exceed a typical fleet.
  • An episode station never has a scan running, a full quarantine or an unfinished ordinary chain part at the episode start, which slightly favours quieter stations: within two hours of an episode its ordinary notifications run at 0.86 of the station's own rate, while ordinary block-to-detection prefixes show 0.86-1.09; activity alone does not single out episode stations.
  • 49/54 (90.7%) coverage of published class-specific variable names, not native-byte certification. Notification names, labels, message text, severity, outcomes and file.* enrichment are collector choices; threat labels are published Dr.Web names, while filenames and hashes are synthetic. No native delivery capture, Elastic sample or live parser round trip was established.
  • The chain is a training correlation: it does not prove that malware executed, changed HOSTS, cloned an Agent or corrected a password. Inventory IP and hostname on connection reports denote the registered asset, not an observed request source.

Sample Output

{
  "@timestamp": "2026-09-26T18:41:25+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "kind": "event",
    "module": "drweb",
    "dataset": "drweb.ess",
    "action": "application-control-blocked",
    "category": [
      "process"
    ],
    "type": [
      "denied"
    ],
    "outcome": "success",
    "severity": 5
  },
  "message": "Application Control prevented launch of C:\\Users\\Public\\Downloads\\invoice.pdf_20260926_183718.exe on WS-IT-112.",
  "observer": {
    "vendor": "Doctor Web",
    "product": "Enterprise Security Suite",
    "version": "13.0.1",
    "hostname": "drweb-srv-01.example.test",
    "ip": [
      "10.20.0.10"
    ]
  },
  "host": {
    "id": "10a56af1-2be3-4381-927f-4d7b1e02c912",
    "name": "WS-IT-112",
    "hostname": "WS-IT-112",
    "ip": [
      "10.20.15.132"
    ]
  },
  "user": {
    "name": "m.makarov"
  },
  "file": {
    "path": "C:\\Users\\Public\\Downloads\\invoice.pdf_20260926_183718.exe",
    "name": "invoice.pdf_20260926_183718.exe"
  },
  "related": {
    "hosts": [
      "WS-IT-112"
    ],
    "ip": [
      "10.20.15.132"
    ],
    "user": [
      "m.makarov"
    ],
    "hash": [
      "57a04e9de7e32d301ddbf6b93359a45f1c17f24e8a45b5e4d79ed28533e3b221"
    ]
  },
  "drweb": {
    "ess": {
      "notification": "Application Control blocked the process",
      "station": {
        "id": "10a56af1-2be3-4381-927f-4d7b1e02c912",
        "name": "WS-IT-112",
        "ip": "10.20.15.132",
        "primary_group": "Workstations"
      },
      "variables": {
        "MSG.AppCtlAction": 5,
        "MSG.AppCtlType": 1,
        "MSG.Path": "C:\\Users\\Public\\Downloads\\invoice.pdf_20260926_183718.exe",
        "MSG.Profile": "Default deny executables",
        "MSG.Rule": "Block untrusted application",
        "MSG.SHA256": "57a04e9de7e32d301ddbf6b93359a45f1c17f24e8a45b5e4d79ed28533e3b221",
        "MSG.StationTime": "2026-09-26T18:41:12+00:00",
        "MSG.TestMode": 0,
        "MSG.User": "m.makarov"
      }
    }
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueMix recurring episodes with ordinary activity; false emits ordinary activity only
anomaly_interval_hours24Finite interval from 6 to 8760 hours, measured from the previous actual episode start
server_namedrweb-srv-01.example.testRegistered Server hostname
server_id9f0ca284-b95a-4cc8-8338-f253a30ab001Server registration UUID in duplicate-station reports
server_ip10.20.0.10Collector inventory context for the Server
server_version13.0.1Metadata for the documented profile; changing it does not establish other-version fidelity
station_groupWorkstationsConfigured primary-group inventory label
ecs_version8.17.0ECS normalization version

Related Generators