Endpoint Security

Prev Next
Verifying your real-Time indicator detection process

After you install and configure your Endpoint Security appliance, you can verify that Endpoint Security is monitoring files and correctly generating alerts by creating a file to match the three built-in IOCs (FIREEYE END2END TEST, FIREEYE END2END OSXTEST, and FIREEYE END2END LINUXTEST). Since you are artificially creating a malicious indicator, a presence alert (for the feyeqatest.exe, feyeqaosxtest, or feyeqalinuxtest file being written to disk) is triggered and shown in the Web UI, and an automatic triage is initiated. If an alert is generated, then event matching and alerts are processing successfully.

To verify your alert process:

  1. On a machine that has the Endpoint Security (HX) xAgent installed, open a program such as Notepad, create a new text file, and add some text to it to make sure it contains data. This file should trigger the appropriate file write event.

  2. Click Save and provide one of the following names for the file:

    • feyeqatest.exe for Windows endpoints

    • feyeqaosxtest for macOS endpoints

    • feyeqalinuxtest for Linux endpoints

  3. An alert should be registered and report back to the Endpoint Security (HX) xAgent appliance. Following the alert, the xAgent initiates creation of an automatic triage package.