Acquisition Started (Endpoint Security)

Prev Next
CEF:0|trellix|hx|9.9.0|Trellix Acquisition Started|Trellix Acquisition
Started|0|rt=Feb 05 2019 17:02:11 UTC dvchost=trellix-01cb28
categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic
Investigation categoryObject=/Host cs1Label=Host Agent Cert Hash
cs1=uP1q4KNadwaber6XLK6BZU dst=10.61.154.186 dmac=00-50-56-01-cb-25
dhost=WIN11b1f2d1fea1 dntdom=WORKGROUP deviceCustomDate1Label=Agent Last
Audit deviceCustomDate1=Feb 05 2019 17:01:52 UTC cs2Label=Trellix Agent
Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS
cs6=Windows 10 Enterprise 17763 externalId=1 cs3Label=Script Name
cs3=Timestamped Triage deviceCustomDate2Label=Triage Request Timestamp
deviceCustomDate2=Feb 05 2019 17:00:22 UTC categoryOutcome=/Success
categorySignificance=/Informational categoryBehavior=/Create act=Acquisition
Status msg=Host WIN11b1f2d1fea1 Timestamped Triage started
categoryTupleDescription=A Host Acquisition was successfully started.