You can monitor operating system changes for each guest image for an Email Security - Server appliance using a graph. The graph shows only the most important events. It shows the flow of activity from one OS change type to another to track the activities leading up to and following malicious OS changes. The graph nodes consolidate related OS change events into groups, such as initiated processes, memory access, and file changes. The red dashed lines indicate malicious change events, such as processes initiated by other processes and code injection.
.png)
Navigate the graph as follows:
View a graph in the alert details page or in a separate window
Expand and collapse graph node details
Expand and collapse malicious alert links from process graph nodes
Zoom in and out
Following are some of the OS change types that the graph can display:
Application Exception
API Call
Command Operation
Code Injection
DLL-loaded
Doc Summary
Exploit Code
File
First Rapid Memory Operation
Folder
Heap Spraying
Hidden Process
Java Call
Malicious Alerts
Mutex
Network
Process
Protection Change
Register Key
Stack Pivot
Thread
WMI Query
Note
The graph query files are automatically updated using the latest security content updates. This enables Trellix to enhance the graph options and add support for more change types without requiring an appliance update.
In the Web UI, click eAlerts > eAlerts > Alerts.
Select an alert. For alerts that have embedded file attachments, expand the alert and select the alert for the embedded malicious file.
Note
Duplicate alerts for files with embedded file attachments cannot be expanded.
In the left navigation bar, click the OS Change Details link for a guest image.
To view or hide additional details on graph nodes that have more available, click the Details link.
To view or hide malicious alerts associated with a node, expand the details and click the Malicious Emails link.
Zoom in and out using the options supported by your device and browser, such as by using the scroll wheel on your mouse or by using standard touch screen interactions.
Drag the graph in the view area to bring off-screen sections into view.
To open the graph in a separate window, click the Graphical View link above the graph.