HTML reconstruction from the Alerts page

Prev Next

The Alerts page also allows you to reconstruct HTML from HTTP events captured in the PCAP.

To reconstruct HTML from the Alerts page:
  1. Click Main_menu.png and from INVESTIGATION, select Alerts.

  2. Click the alert of interest to view its details. A dialog box opens to your right displaying the options for investigating an alert.

  3. Under Asset Details click the Reconstruct to pivot directly to the Artifacts dashboard and reconstruct all HTTP events captured in the PCAP.

  4. From the Web tab, select a record and click + to expand the record.

  5. Select a view of the reconstructed HTML: Sanitized HTML, Raw Unsanitized HTML, and Unsanitized HTML.

Note

Reconstruction is not available for EBC alerts migrated from NDR 1.2.2 to 1.3.0.

Important

A PX Series appliance must be deployed in your network in order to reconstruct PCAP for alerts generated from other Trellix appliances (NX, EX, HX, and CM Series).