Alerts are matches between one or more indicator conditions or source alerts and activity that agents find on their host endpoints.
To investigate alerts, you search forensic data to determine whether an alert represents harmless activity or a system compromise. Information provided by the Endpoint Security (HX) can help you answer the following questions:
How did malware get on a host endpoint?
What IP addresses were accessed?
What URLs were accessed?
What other systems were affected?
What else did the malicious process do?
This part describes the following topics: