The use case illustrates the in-depth investigation of an attack powered by artificial intelligence and telemetry from additional data sources.
Note
Before this use case, we recommend you to go through the use case "Navigating through an attack using Trellix EDR" which detail about Trellix EDR detection of threats, suspicious files, etc. considering the set of threats as examples.
Investigation analysis of an attack is categorized as below:
Create an investigation for in-depth analysis of a threat
Investigate suspicious artifacts using Investigation Guides
Investigate ePO - On-prem or ePO - SaaS convicted files on the endpoint using Investigation Guides
Investigate network communication between endpoint and external environment
Investigate the impact of the suspicious process in the environment
Enrich the investigation using the endpoint snapshot data
Enrich the investigation using SIEM data
Investigate the vulnerabilities in the endpoint
Create an investigation for in-depth analysis of a threat
The Trellix EDR investigation capability expands your analysis by applying in-depth automated intelligence to your existing detection.
You can create an investigation using either the Monitoring dashboard or the Investigating dashboard:
On the Monitoring dashboard, select a threat, then click Actions → Create an investigation.
On the Investigating dashboard, select Create new.
In this use case, the investigation is created for a threat ShinoLocker.exe to do an in-depth investigation powered by artificial intelligence. Now that you have created an investigation, the investigation case is created on the Investigating dashboard for in-depth investigation.
Investigate suspicious artifacts using Investigation Guides
The Trellix EDR investigation capability helps you to investigate "how did the attack happen" with the assistance of artificial intelligence empowered by rich data that is feeding the Trellix EDR back-end. The rich data that is stored in Trellix EDR helps answer several key questions you would be asking as investigators to advance the investigation.
On Investigation Guides, select the answer Running processes with suspicious name to see a list of running processes that looks suspicious.

The details that are answering the question show up in the details pane. You can see suspicious key artifacts such as Devices, Files, Processes on the details pane.
In the list of suspicious artifacts, you can see the process PuttyXs.exe. Putty is a common remote access tool to access an endpoint and it can be used in your environment. But it's not named PuttyXs.exe. This indicates that a process is suspicious.
On the Finding Details pane, select the file path with PuttyXs.exe to see the reputation of a file. The Global Threat Intelligence score is set to 0: Default.

The Trellix GTI reputation for PuttyXs.exe is shown as unknown, which means that the process was not seen earlier in the Trellix environment.
Note
Trellix Global Threat Intelligence is one of the earliest capabilities for detection and stores files and processes reputation.

Trellix GTI helps you to determine the malicious files if the file was seen earlier. Trellix GTI also shows when there is a Known Good file in the environment. Like Windows native files are marked as Known Good. The PuttyXs.exe file path showing reputation 0: Default as unknown, stands out to be different and suspicious.
You can take the file hash of suspicious process from File hashes and add it to Evidence Notes for further investigation.
Now you have investigated that the suspicious artifact PuttyXs.exe is running on endpoint using the answer Running processes with suspicious name on Investigation Guides, you can also investigate the ePO - On-prem or ePO - SaaS convicted files using the answer File convictions from ePO on Investigation Guides.
Investigate ePO - On-prem or ePO - SaaS convicted files on the endpoint using Investigation Guides
The Trellix EDR Investigation Guides capability helps you to see convicted malicious files or malware alerts present on the endpoint.
On Investigation Guides, select the answer File convictions from ePO to see the list of convicted files on the endpoint.

The PuttyXs.exe file path, file hash, and Trellix GTI reputation that are shown in running processes with suspicious name are the same as in File convictions from ePO.
If you look at some of the convictions, the threat name includes ATP. This threat can't be detected easily as the threat is unknown in the environment. But the Endpoint Protection behavioral analysis capability convicted it.

Now that you have investigated the malicious process PuttyXs.exe is running on the endpoint. This investigation is done using Trellix EDR and ePO - On-prem or ePO - SaaS telemetry. You can see how the malicious file originally made its way to endpoints by investigating the network communication between the endpoint and the external environment.
Investigate network communication between endpoint and external environment
When you want to investigate the network communication between the endpoint and external environment, the Trellix EDR Investigation Guides capability helps you to investigate malicious domain names that are in contact with endpoints and lists evidence to determine that they are malicious.
On Investigation Guides, select the answer FQDNs categorized as Malicious Sites or Potential Hacking/Computer Crime by GTI to see the list of suspicious domains.

Select the ShinoLocker.com domain with IP. This domain name looks suspicious based on the domain name, ShinoLocker.com.
You can copy and paste the IP address to Evidence Notes for further investigation.

Select the DNS request icon with the name Shinolocker.com to investigate the socket created between the endpoint and external environment. Click Reputation, the Trellix GTI reputation for the domain name is shown as High Risk.

Now that you know the endpoint in your environment is connected with the external environment, you can investigate the impact of suspicious processes across the environment.
Investigate the impact of the suspicious process in the environment
The Trellix EDR Investigation Guides capability helps you to investigate the impact of suspicious processes in the environment. This investigation helps you to find the number of endpoints where the suspicious file was detected in the environment.
On Investigation Guides, select the answer Running processes with suspicious name to see a list of suspicious names appear on the details pane.

Select the file path with process PuttyXs.exe and click Take an action → Get other devices which have seen this process. Once the action is completed, the affected endpoints are shown in Graph view.

Select Graph view to quickly see the affected endpoints due to the suspicious process PuttyXs.exe.
The Graph view helps to drill down and see what the relationship between endpoints and nodes. There is a linear relationship between some of these nodes that stand out as Key Artifacts and are highlighted.

Click the computer icon to see the endpoint name mentioned in the investigation. In this use case, the endpoint name is podclient—JN2.
On further investigation, one more endpoint — podclient1 is populated. This endpoint appeared due to the last action you took which is Get other devices which have seen this process. The amount of telemetry around this endpoint is limited.
In Graph view, you can see the line connecting between endpoints. When you click on the process that is connecting two endpoints, it shows that the process is PuttyXs.exe.
When you click on the file icon, it shows that the file was responsible for the PuttyXs.exe execution on the endpoint.

Click on the process icons between endpoints in Graph view, the details are shown as PuttyXs.exe.
There are 2 different process icons seen in the graph as one on the endpoint podclient-JN2 and the other on podclient1 with 2 different process ids.
Now that you have completed the impact analysis of suspicious processes in the environment, you have identified the impacted endpoints (In this use case, for example, podclient1 and podclient-JN2). Further, you can enrich the investigation data by capturing the complete image of the impacted endpoints using the Trellix EDR Get endpoint snapshot feature.
Enrich investigation using the endpoint snapshot data
During investigation, if the amount of telemetry is limited for an endpoint, The Trellix EDR Get endpoint snapshot capability helps you to get the forensic image of an endpoint into Trellix EDR.
On the Investigation dashboard, select Graph view and click on the endpoint (in this use case, podclient-JN2). Key Artifacts related to the endpoint are populated to aid you in the investigation.
You can see the sourcing information that populates these Key Artifacts by selecting the Source option.
In Trellix EDR, the Trellix EDR back-end is supported by artificial intelligence and the data is sourced from endpoint trace data, Trellix EDR Agent, and ePO - On-prem or ePO - SaaS.

To enrich the investigation data, The Trellix EDR Get endpoint snapshot feature capability helps you to take a forensic image of the endpoint and populate information about the Investigation dashboard. For example, all the running processes, all the existing network connections, key file information, registry data, etc. All the important information that matters to the investigation, is outside of what Trellix EDR was able to show so far.
On Graph view, select the endpoint podclient1. You see only few Key Artifacts. To enrich the investigation data, go to Take an action → Get endpoint snapshot.
The Get endpoint snapshot action starts feeding source information into the Trellix EDR back-end data lake so that the same artificial intelligence evaluation can occur on the endpoint podclient1 that has been added to the scope of the investigation.

On completing the Get endpoint snapshot action, the information is populated on the existing investigation and the following changes happen:
Potentially new questions on Investigation Guides get answered.
Existing answers on Investigation Guides are enriched with more information.
You start seeing more Key Artifacts and Artifacts.
The changes happen as more data comes in, which is powered by artificial intelligence.
Now that the investigation data is enriched using the snapshot feature, you can enrich the domain data by pulling the malicious FQDNs reputation reports from SIEM.
Enrich the investigation using SIEM data
The SIEM data helps you to enrich the existing investigation data by providing relevant clues to investigate malicious FQDNs.
On Investigation Guides, select the answer Malicious FQDNs reputation reports to know about FQDNs associated with the investigation and details.

The malicious FQDNs appear on Finding Details. Select the malicious domain name Shinolocker.com and then select Take an action → Get events containing this FQDN from SIEM to get details from SIEM.

Trellix EDR can collaborate with a third-party SIEM component. When you query SIEM for additional data, you get the benefit of bringing those extra clues into the Trellix EDR investigation, and also you are going to get it with any analytics those additional sources have already applied.
Now that the investigation data is enriched using the snapshot feature and SIEM data, you can take the appropriate action confidently to eliminate threats.
To avoid future attacks, see if there are any vulnerabilities present in the endpoint.
Assess the vulnerabilities in the endpoint
During investigation, the Trellix EDR vulnerability assessment capability helps you to check the vulnerabilities in the endpoint. The Vulnerability assessment data shows the missing patches, installed patches, exploitable vulnerabilities, etc. to aid you in the investigation.
On Investigation Guides, select Graph View and click on the computer icon to select the endpoint podclient1.
The Device Details appear on the right pane.
You can assess vulnerabilities using the following investigation methods:
Snapshot-based investigations
Threat-based investigations
Device-based investigations
For information about the investigation methods, see Create an investigation for an in-depth analysis of a threat.
Snapshot-based investigations
If the Get Vulnerability Assessment option is available in the dropdown, proceed to step 3.
Threat-Based Investigation
If the Get Vulnerability Assessment option is not displayed, perform one of the following actions:
Select Get Endpoint Snapshot from the dropdown. After this action is completed, the Get Vulnerability Assessment option appears in the Investigation Guides menu.
Manually add a device snapshot to the investigation and wait for the expansion to complete.
Device-Based Investigation
After adding a device for investigation, the Get Vulnerability Assessment option appears if the investigation completes successfully. Proceed to step 3.
If the investigation is unsuccessful, the Get Vulnerability Assessment option is not displayed. In this case, perform one of the following actions:
Select Get Endpoint Snapshot from the dropdown. After this action is completed, the Get Vulnerability Assessment option appears in the Investigation Guides menu.
Manually add a device snapshot to the investigation and wait for the expansion to complete.
Click Take an action → Get Vulnerability Assessment from the device. This action provides below information associated with the endpoint:
Missing Patches
Exploitable Vulnerabilities
Installed Patches
Vulnerability Assessment


With this assessment, you can see the information about installed patches, missing patches, exploitable vulnerabilities, etc. that are applicable for the specific endpoint. In this use case, the endpoint is well-managed, operationally efficient, and software installed on the endpoint are up to date and yet the attack happened using the phishing method. Hence, the investigation must be done from all aspects to identify any phishing attack by an adversary to eliminate threats in the endpoint.