Triage collections

Prev Next

Host endpoint information collected by EDRF Client is provided in downloadable .mans file triage collections. Triage collections are performed automatically for every alert that is captured by the Endpoint Security (HX). You can also request triage collections for hosts with alerts.

Note

Malware alerts do not trigger an automatic triage, as other alerts do.

The Triage Summary page in the Endpoint Security (HX) Web UI provides a summary of information in a triage collection indicative of a potential compromise. This section of the Web UI is called the Triage Viewer. See Reviewing triage collections in the Triage Viewer.

Triage data can also be reviewed using the following methods.

Triage information provides a snapshot of what occurred on a host endpoint around the time of an alert. A triage collection can include the following kinds of information:

  • System information

  • Process activity

  • File activity (*.exe, *.dll, *.sys, *.bat, *.ini)

  • Windows and user directories

  • Registry information, including information about HKEY_CLASSES_ROOT, .bat, .com, .exe, .hta, .pif files, HKEY_LOCAL_MACHINE, software, system, HKEY_USERS, services, and persistence mechanisms

  • User information

  • Task activity, including triggers and actions

  • Port information

  • ARP entries

  • Route entries

  • Prefetch information

  • Disk and volume information

  • Browser URL history

  • File download history

Note

Be sure to update your existing triage collections after upgrading your software. See Updating acquisition data.

For more information, see one of the following topics.