Host endpoint information collected by EDRF Client is provided in downloadable .mans file triage collections. Triage collections are performed automatically for every alert that is captured by the Endpoint Security (HX). You can also request triage collections for hosts with alerts.
Note
Malware alerts do not trigger an automatic triage, as other alerts do.
The Triage Summary page in the Endpoint Security (HX) Web UI provides a summary of information in a triage collection indicative of a potential compromise. This section of the Web UI is called the Triage Viewer. See Reviewing triage collections in the Triage Viewer.
Triage data can also be reviewed using the following methods.
You can process and view triage data in the Audit Viewer. See Reviewing forensic data in the Audit Viewer.
You can download the entire triage
.mansfile to review all triage data in Redline. See Reviewing forensic data in Redline.
Triage information provides a snapshot of what occurred on a host endpoint around the time of an alert. A triage collection can include the following kinds of information:
System information
Process activity
File activity (
*.exe,*.dll,*.sys,*.bat,*.ini)Windows and user directories
Registry information, including information about HKEY_CLASSES_ROOT,
.bat,.com,.exe,.hta,.piffiles, HKEY_LOCAL_MACHINE, software, system, HKEY_USERS, services, and persistence mechanismsUser information
Task activity, including triggers and actions
Port information
ARP entries
Route entries
Prefetch information
Disk and volume information
Browser URL history
File download history
Note
Be sure to update your existing triage collections after upgrading your software. See Updating acquisition data.
For more information, see one of the following topics.