> For the complete documentation index, see [llms.txt](https://docs.bfore.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.bfore.ai/docs/console/disrupted-attacks/attack-details.md).

# Attack details

The **Attack detail** page shows everything PreCrime knows about a single attack. Open it from the Disrupted attacks list, the dashboard's top attacks table, or a takedown's **Details** button.

<figure><img src="https://805658693-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcO8fwtDPLlpySjcpjpC5%2Fuploads%2Fl2n8FM5QNFd6E09Tdb7w%2Fimage.png?alt=media&amp;token=31448c00-7b7c-48d1-b063-f555ef722465" alt=""><figcaption></figcaption></figure>

## Header

* The attack URL, with a copy button.
* **See subdomains** - if the attack has related subdomains, jumps to the subdomains section.
* The takedown control: **Start takedown**, **Cancel takedown**, or **Restart takedown** for Admins depending on the takedown's state, or a status chip (see [Managing takedowns](/docs/console/takedowns-list/managing-takedowns.md)).
* **Protected asset** and the **Alerted Timestamp** (or **Resurged at** date for resurgent attacks).
* **Averted victims** - total connection attempts blocked since disruption started.
* **Attack cost prevented** - the estimated financial loss avoided.
* **False positive** - report the attack as a false positive (see [Reporting false positives and negatives](/docs/console/disrupted-attacks/reporting-false-positives-and-negatives.md)).

## Export as…

The export menu offers:

* **CSV file** and **JSON file** - download the attack's core data.
* **PDF file** - opens the browser print dialog for a printable report.
* **Copy link** - copies the page URL to your clipboard.

## Disruption partners

<figure><img src="https://805658693-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcO8fwtDPLlpySjcpjpC5%2Fuploads%2FE0vzscjU1paADTPdQvLi%2Fimage.png?alt=media&amp;token=017c3515-d84c-4423-b4f5-b9b6506a4de6" alt=""><figcaption></figcaption></figure>

The partners currently blocking the attack, each marked **Disrupted** (green) or **Submitted** (amber). Submitted attacks mean that the malicious URL/domain has been shared with the partner, and we're waiting for it to be actioned by them. **View all** opens the full partner list with what each partner does and how you benefit. Disruption blocks traffic but does not remove the infrastructure - use **Start takedown** for removal.

If disruption is not enabled for your account, the panel says so and asks you to contact your account manager to learn more. When you are viewing an attack that belongs to a child company in a multi-tenant setup, the message names that company specifically (for example, "Disruption is not enabled for Alpha Corp").

## AI Feedback and screenshot

The **AI Feedback** card shows the categorized evidence PreCrime collected about the attack. **View all** opens the full details with a description of each note. The **Screenshot** card shows a capture of the malicious site; click it to view full size.

## Victims averted chart

<figure><img src="https://805658693-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcO8fwtDPLlpySjcpjpC5%2Fuploads%2FxvNn5CJYh2wsdj0lOjUX%2Fimage.png?alt=media&amp;token=ff1c2ec5-73fe-4b7f-9b94-4c73150628f3" alt=""><figcaption></figcaption></figure>

A chart of blocked connection attempts over time, with its own date range picker and a bar/line toggle. If your selected range ends before disruption started, the page tells you the disruption start date so you can adjust the range.

## Attack lifecycle

<figure><img src="https://805658693-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcO8fwtDPLlpySjcpjpC5%2Fuploads%2FcvLwM9cOvdxk62EOaOpk%2Fimage.png?alt=media&amp;token=4af7b834-c08c-4d2a-9a3a-2d3ecbba1255" alt=""><figcaption></figcaption></figure>

A timeline of the actions taken on the attack, from **Confirmed Attack** through **Disrupted** and each takedown phase, up to resolution. Completed steps are marked; upcoming steps appear unreached.

When a takedown is cancelled, the timeline shows a **Cancelled** step and the takedown control in the header is replaced by a status chip. Click the chip to see the cancellation reason.

## Subdomains

For domain attacks, the **Subdomains** section lists subdomains observed under the attack domain. The table shows two columns:

* **URL** - the subdomain address, with a copy button.
* **Updated** - how long ago the subdomain record was last updated, shown as a relative time (for example, "5 Days").

Each row also has a **Takedown** column. For subdomains that have not yet had a takedown started, a **Start takedown** button appears there (visible to Admin users). Subdomains that already have a takedown display their current takedown status instead.

> **Screenshot needed:** \[The Subdomains section showing the table with URL, Updated, and Takedown columns, the bulk takedown button in the card header, and the pagination footer displaying a result count]

### Selecting subdomains and requesting bulk takedowns

Admin users can request takedowns for multiple subdomains at once:

1. Check the box next to each subdomain you want to include, or use the **Select all subdomains** checkbox in the table header to select every eligible subdomain on the current page at once.
2. Once at least one subdomain is selected, the **Start takedown** button in the card header becomes active.
3. Click **Start takedown** to open the takedown confirmation dialog.
4. Confirm to submit the takedown request for all selected subdomains.

Not all rows can be selected:

* The **parent domain** (the attack domain itself) appears in the list when there is more than one page of results - it is annotated with **(this domain)** and its checkbox is disabled.
* Subdomains that already have a takedown show their takedown status and cannot be selected again.
* Resurgent subdomains with no takedown on record show a **Not started** status and are not selectable.

When the entire result set fits on a single page and the parent domain is present, it is removed from the list automatically and the total count is adjusted to reflect only the subdomains.

### Pagination

The section displays up to 20 subdomains per page. When there are more results, a pagination bar appears below the table showing the total count (for example, "21 Subdomains") and controls to move between pages. If there are no subdomains, the pagination bar is hidden and the table shows a **No data available** message.

If the subdomains list cannot be loaded, the table shows an **Unable to load data** message with a **Retry** button. Click **Retry** to attempt to reload the list.

## Technical details

<figure><img src="https://805658693-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcO8fwtDPLlpySjcpjpC5%2Fuploads%2F5Zv8gnQDVzlbESqReMgh%2Fattack-technical.png?alt=media&amp;token=0db3c468-b156-43fe-beff-9b80b454a2de" alt=""><figcaption></figcaption></figure>

Three tabs of raw infrastructure data:

* **DNS Records** - address, domain name, TTL, record class and type, and server.
* **SSL Certificate** - subject, thumbprint, serial number, validity dates, organization, and issuer.
* **Whois** - the domain's WHOIS registration records.

Records that are still being collected show a processing message - check back shortly.

## Domain connections

A graph and table of domains connected to the attack: **Newly-observed domain**, **Known benign**, **Known malicious**, or **Predicted malicious**.

## Viewing attacks across child companies

If your account manages child companies and you open an attack that belongs to a child company, the page loads all metrics and disruption details scoped to that child company automatically. A banner at the top of the page identifies which company's data you are viewing. Charts, blocked-hit counts, attack cost figures, and the disruption partners list all reflect the child company's configuration rather than your parent account's.

If any of those data sections cannot load, each affected card shows a **Retry** button so you can reload just that section without refreshing the whole page.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.bfore.ai/docs/console/disrupted-attacks/attack-details.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
