When the investigation case is created, EDRF automatically gathers, summarizes, and visualizes evidence based on the activity details available and iterates as the investigation evolves. During the investigation, you can add additional evidence related to a threat from multiple sources to widen the scope.
EDRF is supported by artificial intelligence and the data is sourced from endpoint trace data, EDRF Client, ePO - On-prem or , SIEM, and endpoint snapshot.
For example, when the investigation is created for a threat, EDRF shows malicious files, processes, network connections, API calls, command lines, user information, etc. are responsible for the execution of an attack with a number of impacted endpoints.
To expand the investigation case:
If you find any of these malicious artifacts available on endpoints, you can take snapshot of that endpoint and upload it as evidence to an existing or new investigation. This snapshot brings all auto-start entries and registry changes to the investigation which is not populated in EDRF by default.
If you see an FQDN used during the attack and want to know the details such as vulnerability reference, destination IP, severity, reputation, timestamp, connection direction, associated file and process names, target and attacker host names, etc. about it, you can get it by integrating EDRF with SIEM.
You can get the respective endpoint web control alerts, file and process convictions from ePO - On-prem or ePO - SaaS to expand the investigation.
You can run the vulnerability assessment on the endpoint to know about missing updates, exploitable vulnerabilities, and installed updates from ePO - On-prem or ePO - SaaS.
You can use the following ways to import data to expand the investigation:
Add evidence to the investigation case
Get endpoint snapshot
Get SIEM data
Get events containing the FQDN from SIEM
Get events from SIEM containing this IP as a destination
Get the investigating endpoint-related information from ePO - On-prem or ePO - SaaS:
Web control alerts from the endpoint
File convictions happened on the endpoint
Process convictions happened on the endpoint
Vulnerability assessment for the endpoint
Get other endpoints that have the AutoStart entry configured
Get other devices that have NetFlow entries containing the IP
Get other endpoints that have seen the process
Get process binary creation entry in the last 24 hours of MFT records.
When you are importing additional data, you can check the status information such as in progress and completed in Task Queue for every manual action that you perform in EDRF.
Note
The successful manual action to import data can be performed only once in the specific investigation created. The option to import disappears for the endpoint on the successful action execution.
Based on the imported data from different sources:
More endpoint-related data would be populated, and the investigation case expands. This data is categorized as Artifacts, Key Artifacts, and Key findings to help you in the investigation.
The number of key findings or hypothesis in investigation guides are increased or existing data expands.
For example, if there are any uncommon processes executed on the endpoint, the question - are there any uncommon processes? Added to key findings with the response of processes list and their details. If there are more uncommon processes executed later, the data evolves as the investigation progresses.
More data added to the list of investigated items such as processes, files, IPs, network connections, etc.
Adds other endpoints where the suspicious artifacts are present during the investigation.
The investigation details are shown on different views to help you do the investigation quickly:
Summary view — This is the default view. The summary view allows you to access the threat from the threat list. When you click the threat, the details of that threat appear in the Monitoring dashboard in a new window. The summary view also displays investigation guides with questions answered by the system and findings. When you click an investigation finding, the Finding Details pane appears in the right pane with the list of processes.
Graph view — It displays the list of artifacts graphically that might be impacted by the threat for the current investigation. You can use the filter option to filter which type of artifact you want to analyze.
Investigation guides view — Displays the investigation guides with the questions answered by the system and the findings to help you understand and analyze the investigation better and help close it quickly. When you click an investigation finding, the Finding Details pane appears and displays the list of artifacts or nodes.
Table view — Displays the list of artifacts and their respective threat details in a table view. You can click a node to view the appropriate details for that node in the right pane. You can also use the Export option to export all artifacts listed in the table.
Affected devices view — Displays the list of devices and their host name, operating system version, ePO - On-prem tags, and identifier. You can click a device to view the Device Details pane.
Note
The Affected devices list only three devices. To check the remaining affected devices, click View All. This page navigates you to the Monitoring dashboard where all the affected devices are listed.
In the Affected Devices pane, you can also identify the devices with exploitable vulnerabilities to help you focus your investigation.
Add evidence to the investigation case
You can add evidence details such as endpoint, external domain, IP, and device snapshot to an existing investigation or new investigation to enrich or provide more insightful information for the investigation.
Select Menu → Investigating to open the Investigation page.
Select an existing investigation, then on the upper right corner, click Options → Add to Current Investigation.
Device — Enter the device host name
External Domain — Enter the external domain address.
External IP — Enter the external IP address.
Device Snapshot — Click Choose File, browse to the location and select the required file, and click Open.
Note
Ensure the Device Snapshot file size does not exceed 50 MB.
Click Submit.
Evidence such as Device, External Domain, and External IP can be added only once in the same investigation. But, Device Snapshot can be added multiple times.
Get endpoint snapshot
The EDRF Get endpoint snapshot capability enables you to take a forensic image of the endpoint and populates information about artifacts such as running processes, existing network connections, key file information, auto-start entries, registry data, etc. to expand the investigation.
You can get the endpoint snapshot in two ways:
Get the endpoint snapshot using the Investigating dashboard
Get the endpoint snapshot using the phoenix tool
Get the endpoint snapshot using the Investigating dashboard
When you have created an investigation for a threat and want to add endpoint snapshot as an extra evidence, you can get the endpoint snapshot automatically.
On the Investigating dashboard, select Graph view and click on the endpoint. Artifacts and key artifacts related to the endpoint are populated to aid you in the investigation.
You can see the sourcing information that populates artifacts by selecting the source option.
On Graph view, select the endpoint name. You can see a few key artifacts. To enrich the investigation data, go to Take an action → Get endpoint snapshot .
Get the endpoint snapshot manually using the phoenix tool
When you have created an investigation for the suspicious endpoint, you can get the endpoint snapshot manually as an evidence and upload it to an existing investigation.
The phoenix tool is already installed with the EDRF client on endpoints.
Open the command prompt and run as an administrator.
Run
cd C:\Program Files\McAfee\MAR\tools\phoenix.Run
mkdir %temp%\phoenix\result.Run
phoenix_engine_main.exe -j jobs\mi_snapshot_job.json -o %temp%\phoenix\result --compress="1"The endpoint snapshot .zip file is created at the
%temp%\phoenix\resultfolder.Add the endpoint snapshot to the investigation.
For details about adding evidence to an existing investigation, see section Add evidence to the investigation case.
When the snapshot of an endpoint is generated or uploaded, EDRF also evaluates that data to expand the investigation.
Get SIEM data
The SIEM data helps you expand the existing investigation by providing insightful information about an FQDN such as vulnerability reference, destination IP, severity, reputation, time stamp, connection direction, associated file and process names, and target and attacker host names, etc.
For details about the integration, see EDRF integration with SIEM.
To get the insightful information about malicious FQDNs:
On the Investigating dashboard, select Graph view and click on the endpoint.
On Investigation Guides, select the answer Malicious FQDNs reputation reports to know about FQDNs associated with the investigation.
The malicious FQDNs appear on the finding details pane.
Select the malicious domain name and then select Take an action → Get events containing this FQDN from SIEM to get details from SIEM.
Get the endpoint-related information from ePO - On-prem or ePO - SaaS
You can get the endpoint-related information such as file and process convictions and web control alerts. Also, you can assess vulnerabilities present on the endpoint to know details such as exploitable vulnerabilities and missing updates.
On the Investigating dashboard, click Investigated items and select Graph view.
The list of artifacts and key artifacts are shown on Graph view. When you click an artifact, the details are shown on the finding details pane.
Select the Devices artifact to get details from ePO - On-prem or ePO - SaaS, the endpoint names are shown on the pane.
On the finding details pane, select the endpoint name and then click Take an action to get these key details from ePO - On-prem or ePO - SaaS:
Web Control alerts from the endpoint
File convictions happened on the endpoint
Process convictions happened on the endpoint
Vulnerability assessment for the endpoint
Note
The vulnerability assessment feature is available with EDRF client 3.2.x or later.
This option is available only when you add an endpoint as evidence or the endpoint snapshot of the selected endpoint to an existing investigation. This vulnerability assessment report is only available for up to 12 hours. Later, the report is updated and available on refreshing the vulnerability assistance option.
Once the action is completed successfully, click on the affected device to check the device details. To download a vulnerability assessment, installed patches, or missing patches report:
On the Device Details pane under Vulnerability Assessment, Installed Patches, or Missing Patches, right click on CSV.report → Save link as.
Save the report with extension .csv.
Get other endpoint details where the suspicious artifacts are present
To widen the scope of an investigation, you can fetch other endpoint details where the suspicious artifacts are present in the environment. This helps to analyze and determine the complete impact of an investigation.
On the Investigating dashboard, click Investigated items and select Graph view.
Select the Auto-start entries artifact to check the details of auto launch applications on endpoint startup.
Select Processes or Auto-start entries and then click Get other endpoints which have seen the respective process or auto-start entry configured.
Once the Get other endpoints action is completed, other impacted endpoints are added to the investigated items. You can also see the endpoint details about Graph view as the investigation case expands.