Active Response offers continuous visibility and insights into your endpoints, so you can identify breaches as they happen. It helps security practitioners query the current security posture, improve threat detection, and perform detailed analysis and forensic investigations.
If Active Response is installed as an extension on ePO - On-prem devices added to Trellix ESM, you can use Active Response to search from the Trellix ESM. The search generates a list of current endpoint data, allowing you to:
View the list of search results
Create a watchlist populated with search results
Append Active Response search data to an existing watchlist
Add a data enrichment source populated with search results
Export search data
Note
Searching with Active Response uses Trellix® Data Exchange Layer.
When using Active Response on Trellix ESM note that:
High availability (HA) receivers do not support Trellix® Data Exchange Layer.
Date formats from an Active Response search are returned as
2018-11-05T23:10:14.263Zand not converted to the Trellix ESM date format.When you append Active Response data to a watchlist, the system does not validate the data, which means you might add data to a watchlist that doesn't match its type.