You can investigate triage collection and data acquisition .mans files in Redline.
When you view data in Redline, you are examining a snapshot of a host endpoint system at the time of an alerting event for clues about how an attacker might have operated. If you know that a host endpoint downloaded a file, you can look at suspicious file paths and at what else was happening around the time that the host downloaded the file. There are many investigative paths you can search for additional information.
For example, you can use Redline's Timeline tool to search for network-related activity (by IP or DNS name) or for host endpoint activity (such as a malicious file name) based on a file name, process ID, or timestamp. Timeline can help you discover which processes caused specific activity. TimeWrinkles and Timeline Filtering can help you see what a process actually did, files it created, network connections it generated, or registry keys it changed. This process helps you determine the scope and severity of compromise.
Install Redline on the computer you will use for investigation or analysis. Instructions are provided in Installing Redline .
Download the triage collection or data acquisition
.mansfile that you want to review onto the same computer. For more information, read Downloading forensic data .
Installing Redline
You can download Redline software from https://www.fireeye.com/services/freeware.html. You can download the Redline user documentation at the same site.
Investigating the data in Redline
Double-click the
.mansfile.Redline opens and imports the triage collection.
On the Redline Start Your Investigation page, hover over I am Reviewing a Triage Collection from HX until the block turns red. Then click the red block or the Investigate link.
Note
If you have previously opened the
.mansfile in Redline and saved your analysis, you can open the saved analysis in the following ways:On the Redline Home page, select Open a Saved Analysis.
On the Redline menu, select the triage collection.
The Timeline view opens. Use the filtering feature to focus on your investigative lead.
Investigate leads in your triage and data acquisition data. Follow threads of information for each until you can find hard evidence of suspicious activity.
Note
There is no set path for completing a
.mansfile investigation. Each investigation depends on what you find as you follow up each lead.Follow up in the Endpoint Security (HX) appliance.
For example, depending on your investigation findings, you can acquire files or request additional data acquisitions for further analysis. See Acquiring forensic data . You can also contain a host endpoint that you believe is compromised. See Containing hosts .