You can configure Process Tracker to automatically identify known threats.
Enable enrichment: By enabling the Enrichment feature in the module's configuration, every process event can be automatically analyzed. Events are tagged with a status, such as Malicious or Benign. This allows you to filter the grid for all events that have been flagged as malicious.
Enable alerts: When you enable alerts, the module will automatically generate an alert in the EDRF console whenever an event is enriched with a Malicious status. This function helps to automate and speed up the detection of known threats.
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat hunting with advanced detection modules