You can create a list of every endpoint and server that a compromised account accessed.
Use the Search username field to search for all activity associated with the compromised account.
In the graph view, every connected hexagon represents a system the account logged into or attempted to log into.
To compile a list of all unique hostnames and IP addresses, use the grid view. Filter or sort by the Src Host and Tgt Host columns. You can use the Export CSV function to save this list for your incident report.
Endpoint Detection and Response with Forensics (EDRF) > Investigate potential threats with EDRF > Analyzing forensic data > Analyze forensic data using HX modules > Investigate malicious authentication patterns with Logon Tracker
Endpoint Security (HX) > Endpoint Security (HX) Server 10.x User Guide > Overview > The Endpoint Security (HX) Web UI > About the Endpoint Security (HX) Web UI > Hosts menu
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat hunting with advanced detection modules > Detection using Logon Tracker