Viewing OS change details in a graph in the Web UI

Prev Next

You can monitor operating system changes for each guest image for an Email Security - Server appliance using a graph. The graph shows only the most important events. It shows the flow of activity from one OS change type to another to track the activities leading up to and following malicious OS changes. The graph nodes consolidate related OS change events into groups, such as initiated processes, memory access, and file changes. The red dashed lines indicate malicious change events, such as processes initiated by other processes and code injection.

EX_OSChange_Graph_scap.png

Navigate the graph as follows:

  • View a graph in the alert details page or in a separate window

  • Expand and collapse graph node details

  • Expand and collapse malicious alert links from process graph nodes

  • Zoom in and out

Following are some of the OS change types that the graph can display:

  • Application Exception

  • API Call

  • Command Operation

  • Code Injection

  • DLL-loaded

  • Doc Summary

  • Exploit Code

  • File

  • First Rapid Memory Operation

  • Folder

  • Heap Spraying

  • Hidden Process

  • Java Call

  • Malicious Alerts

  • Mutex

  • Network

  • Process

  • Protection Change

  • Register Key

  • Stack Pivot

  • Thread

  • WMI Query

Note

The graph query files are automatically updated using the latest security content updates. This enables Trellix to enhance the graph options and add support for more change types without requiring an appliance update.

To view the OS Change graph:
  1. In the Web UI, click eAlerts > eAlerts > Alerts.

  2. Select an alert. For alerts that have embedded file attachments, expand the alert and select the alert for the embedded malicious file.

    Note

    Duplicate alerts for files with embedded file attachments cannot be expanded.

  3. In the left navigation bar, click the OS Change Details link for a guest image.

  4. To view or hide additional details on graph nodes that have more available, click the Details link.

  5. To view or hide malicious alerts associated with a node, expand the details and click the Malicious Emails link.

  6. Zoom in and out using the options supported by your device and browser, such as by using the scroll wheel on your mouse or by using standard touch screen interactions.

  7. Drag the graph in the view area to bring off-screen sections into view.

  8. To open the graph in a separate window, click the Graphical View link above the graph.