When the investigation is created with threat metadata or evidence is added manually, the processes, correlate, and show related data to expand the investigation.
classifies the sourced data into different artifacts such as devices, user accounts, auto-start entries, FQDNs, DNS lookups, IPs, files, processes, network connections, and services. These artifacts can be associated with malicious activity detected by . connects each of these artifacts and shows it on graph view to help you understand the attack pattern.
For better data visualization, you can see the investigated items on Graph view:
On the Investigating dashboard, select Investigated items → Graph view.
On Graph view, select key artifacts or artifacts to filter important details discovered for the current investigation.
Artifacts or key artifacts are highlighted on the graph view.
Note
On the Graph and Table views, you select artifacts or key artifacts to check the appropriate details on the graph area.
On Investigated items, select an artifact to check the details of:
Device — host name, identifier, ePO - On-prem tags, and evidence notes.
Note
After the investigation case is created, the affected devices count is limited to top three devices based on the severity when investigating a threat story. This is to limit the data expansion.
File — file path, file hashes, and evidence notes.
IPs — IP address and evidence notes.
Network connection — authenticity of the connection, source and target IP, source and target port, process name, file path, and evidence notes.
Process — process name, process ID, prevalence, suspicious indicator, and evidence notes.
Auto-start entry — entry location of the event, command line used, associated file, and its path, registry key used, etc.
You can select the respective artifact and fetch more details from other data sources such as ePO - On-prem or ePO - SaaS, SIEM, and the endpoint itself (endpoint snapshot). Also, you can check the impact of these artifacts on all endpoints in the environment.
For details about importing data into an existing investigation, see Import threat related data into an existing investigation.