Reviewing triage collections in the Triage Viewer

Prev Next

Endpoint Security (HX) provides a summary of the triage on the Triage Summary page when a triage collection contains alerts or other information that might indicate a system compromise. The Triage Summary is a high-level view of the triage data.

Note

If the sum of the unzipped sizes of the audits included in a triage collection exceeds 3 GB, an error message displays indicating that the acquisition cannot be viewed in the Triage Viewer (or in the Audit Viewer).

To view all of the triage data, use the Audit Viewer or Redline.

TriageSummary.png

The left side of the Triage Summary lists all the alerting processes on the host endpoint included in the triage collection. Icons that identify the types of alerts that were encountered for each process on the host: exploit (XPLTicon.png), presence (PRSIcon.png) or execution (EXCicon.png). If an exploited process is terminated or is blocked from launching, the block icon (IconBlk.png) appears. If an attempt to block or terminate an exploited process fails, the block failed icon (FAILicon.png) appears. Click on these icons to obtain more information.

Timelines at the top of the Triage Summary show when processes were created, network accesses (including DNS, IP, and URL accesses) occurred, and registry and file writes were performed by an alerting process. The red dots in the time lines identify the alerts as they occurred over time. Click any red dot (or its event block) to see more detailed information about that alert.

The bottom of the Triage Summary page provides more detail about the alerting process you have selected and shows:

  • Processes that were created

  • Domains that were accessed

  • IP address connections that were made

  • URLs that created alerts because they matched an IOC (other URLs are not included)

  • Exploits that were detected

  • Registry keys that were created or changed

  • Files that were written

  • Icons that identify the types of alerts that were encountered on the host: exploit (XPLTicon.png), presence (PRSIcon.png) or execution (EXCicon.png).

  • If an exploited process is terminated or is blocked from launching, the block icon (IconBlk.png) appears. If an attempt to block or terminate an exploited process fails, the block failed icon (FAILicon.png) appears.

You can click on process IDs, URLs, files, exploits, and registry keys to see more detailed information about them.

You can click on the icon for an alert type in the details pane to mark the alert as a false positive. For more information, see Defining alerts as false positive on the Triage Summary page .

Use the buttons at the top of the Triage Summary:

  • Request containment—Request to contain the host for which the triage was generated.

  • Cancel containment request—Cancel a request to contain the host for which the triage was generated.

  • Triage Summary—Select other triage collections for the same host.

  • Download full triage—Download the triage .mans file to your computer. The full triage can then be reviewed using Redline. For more information, see Reviewing forensic data in Redline.

  • Acquire process details —Request a process detail acquisition for the process selected in the left pane. This request acquires details about the process. You can review the data in the Audit Viewer. If you download the acquisition, the data can be reviewed in Redline. The acquired data includes strings in memory for the process.

Accessing the Triage Summary

Note

If the triage is still being processed, the Triage Summary is not available. A message appears in the Detail pane.

To view a triage in the Triage Summary:
  1. On the Acquisitions page, select the acquisition. If the triage contains alerts, a Triage Summary is automatically created and a link appears in the Detail pane for the selected acquisition link.

    On the Hosts page, expand (click the ExpandIcon.png icon) the host for which triage data was collected and review the host alert details.

  2. Click Triage Summary in the Detail pane of the Acquisitions page. The Triage Summary for the selected triage acquisition appears.

    At the bottom of the host alert details section of the Hosts page, click View triage for the triage you want to review.