Host alert details provide detailed information about the alerts for a host and the data, file, and triage acquisitions that are made for the host.
Prerequisites
Admin, Analyst, Senior Analyst, or Investigator privileges (full access)
Accessing the page
To access host alert details:
Select Manage Hosts from the main menu at the top left of the page.
Click Hosts With Alerts, and click the expand icon (
) next to the host for which you want alert detail information.To return to the Hosts with Alerts page, click the collapse (
) icon on the upper left corner of the page or select Hosts with Alerts from the Hosts menu at the top of the page..png)
The following options are available at the top of the page.
Request Containment—You can control containment of the host endpoint. Depending on the host's current containment state and your Endpoint Security (HX) Web UI user role, you can request containment of the host, approve containment of the host, or cancel or stop containment of the host. The containment button at the top of the page changes depending on the containment state for the host endpoint. See The containment process .
Note
You cannot contain Linux endpoints.
Acquire—You can select an option from this menu to acquire a file, triage, standard or comprehensive investigative data, a quick file listing, or agent diagnostics for the selected endpoint. The list of items that can be acquired varies, depending on the operating system of the host endpoint.
Delete Alerts—You can delete all alerts for the host.
Note
Timestamps in the Web UI are presented in UTC time.
Below the host information are details about the alerts and quarantined files.
The Host Alert Details page contains two tabs: the Alerts tab and the Quarantines tab. A list of acquisitions appears at the bottom of the page.
Alerts tab
The Alerts tab can be found under the Investigate tab on the main menu of the Endpoint Security (HX) Web UI. Alerts in this section are grouped based on certain criteria, which is explained in Understanding alert grouping. When grouped, a single alert is shown with multiple instances. Alerts in this section are sorted by priority, with highest priority alerts at the top of the list. If an alert includes a false positive condition, the alert is flagged with the false positive (
) badge.
.png)
.png)
The following table lists some of the actions you can take on the alert details page.
Action | How to | Description |
|---|---|---|
View alert details | Select an alert in the list on the left to display its details on the right. | Details for an alert will vary based on the type of alert you selected. |
Filter alerts by disposition | Use the Disposition drop-down menu to filter the data by false positive disposition. | You can show All, False Positive, or Not False Positive alerts by using Disposition. For more information about how hosts are filtered by disposition, see About false positive badges . |
Acknowledge or Unacknowledge an alert | Click Acknowledge to acknowledge an alert or click Unacknowledge to unacknowledge an acknowledged alert. | Acknowledgment is a way for you to indicate that you have reviewed the alert. Acknowledged alerts are no longer marked as new alerts in need of review, but they remain in the system for further investigation or reference. |
Acquire file | Click Acquire File in the alert details. | Use Acquire File to acquire an infected file from its original location. The file acquisition appears in the Acquisitions section of the page, at the bottom, and on the Acquisitions page in the Web UI. |
Acquire process details for an Exploit alert | Click Acquire process details. | The process details acquisition appears in the Acquisitions section of the page and on the Acquisitions page in the Web UI. Note that the initially exploited process is listed in the alert details. If the exploit was blocked, the block actions performed are shown. |
View Storytime Visualization. For the link to appear, the alert must be an IOC or EXG alert and must have an auto-triage package | Select an alert on the left to display its details on the right. If the alert has many events, page through each event until you find a Storytime View section on the lower portion of the Alert Details panel. Click the Click to View link. ![]() | The Storytime Visualization shows the sequence of events that led to the detection. The graphical representation shows the critical path to the event node that triggered the detection. |
Presence and executed alerts
If you click the Alerted on or Alerted nnn times on box, an option appears that allows you to mark the alert as a false positive .
The number of indicator rules that generated the condition is shown.
.png)
This count is not platform-specific, but represents the total number of indicator rules that include the condition that triggered the alert, regardless of operating system platform. The same condition may be included in multiple indicator rules.
You can review the indicator rules that generated the alert, by selecting an indicator rule name. The indicator rules appear on the Rules page.
Click the Acquire File button in the alert details to acquire the infected file from its original location. The file acquisition appears in the Acquisitions section of the page, and on the Acquisitions page. When the file acquisition is complete, download the file acquisition from either location.
Exploit alerts
The initially exploited process is listed in the alert details. If the exploit was blocked, the block actions that were performed are shown.
Click the Acquire process details button in the alert details to acquire process details about the exploit alert. The process details acquisition appears in the Acquisitions section of the page, and on the Acquisitions page. When the process detail acquisition is complete, download the process details from either location.
About malware alerts
For malware events, a confidence level of signature (
) or heuristic (
) is shown in the alert details.
An alert with a signature (
) confidence level is confirmed malware that matches a Trellix malware definition.An alert with a heuristic (
) confidence level is suspected malware, identified through heuristic means. The condition that triggered the alert has characteristics of known malware, but does not match any Trellix malware definition.
The following table describes the possible detail information provided for a malware alert on the Alerts tab. Some data is not provided for different types of scanned objects.
Section | Field | Description |
|---|---|---|
Event details | Alerted | The time elapsed since the malware alert was reported Endpoint Security (HX). |
Detection time | The time when the malware alert was detected by the Endpoint Security (HX) xAgent. | |
Scan details | Scan type | The type of scan indicates whether the scan occurred when a resource (for example, a file) is accessed or as a scheduled scan. Possible values are On-access or On-demand. |
Scanned object | The type of object scanned. Possible values are Bootsector, File, Process, or Registry. | |
Malware details | Malware name | The name of the detected malware. |
Malware type | The type of malware. Possible values are Malware, Spyware, Adware, Dialer, Potentially unwanted program, or Archive bomb. | |
File details | Status | The action take on the file. Possible values are Alert, Cleaned, or Quarantined. Alert appears when quarantine is not enabled in your environment or when the Trellix Endpoint Security (HX) xAgent fails to clean the infected file. Cleaned appears when an infected file is deleted, but the rest of the submission is not quarantined. Quarantined appears when a file introduced by malware is automatically deleted from the system (but is in the quarantine area). |
File path | The fully qualified path of the file. | |
MD5 | The MD5 hash of the file. | |
SHA1 | The SHA1 hash of the file. | |
File size | The size of the file. | |
File compressed | Indicates whether the file was compressed. | |
File created | The timestamp when the file was created. | |
File modified | The timestamp when the file was last modified. | |
File last accessed | The timestamp when the file was last accessed. | |
Process details | Process path | The fully qualified path to the process |
PID | The process ID | |
Username | The user that invoked the process. | |
Registry details | Key | The name of the registry key. |
Value | Value of the registry key. | |
System details | Content version | The content version. |
Quarantines tab
The Quarantines tab shows the infected files that malware protection has quarantined for the host. When malware remediation (quarantine) actions are enabled, infected files are automatically copied to a quarantine area where they can be reviewed by your system analysts. They are stored in the quarantine area until the quarantine aging period has passed. The quarantine aging period can be configured on the Quarantined Files Aging tab. The default is 90 days.
The fields on the Quarantines tab are configurable. Click on the
button to select fields for the tab.
.png)
You can filter the list of Quarantines by clicking a column header and entering the filter criteria. Click Filter when done. You can also order alerts based on the MD5 hash in ascending or descending order.
The following options are available for files listed in the Quarantines tab grid. Click on the
button to select an option.
Select Acquire File to acquire the infected file from the quarantine area for further examination.
Select Restore File to restore the infected file from the quarantine area to its normal location on the endpoint.
Select Delete File from Quarantine to delete the file from the quarantine area.
Malware scans
The Malware Scans tab shows the status of all requested, running, and completed malware scans on your host endpoint. This is also known as the scan summary.
.png)