You can perform the following actions on an Endpoint Security (HX) host details page:
Contain Helix Enterprise Endpoint Security (HX) host endpoints to restrict their ability to communicate on the network.
Acquire forensic data to investigate alerts and suspicious activity on the host endpoints.
To open a host details page, do one of the following:
From the main menu, select Explore > Entities and click the host in the Asset Name column.
Click the host in the Asset-Based Alert Correlations widget on the Summary Dashboard.
From the main menu, select Investigate > Correlated Alerts and click the host in the Asset-Based Alert Correlations widget or Asset-Based Alert Correlation table.
To perform remediation and data extraction:
To contain a host, click Contain. To remove a host from containment, click Uncontain.
To acquire a file from a host, click Acquire > File. In the Acquire File dialog box, specify a file name, full path to where the file should be stored, and the request mode. Click Acquire.
To acquire a triage package from a host, click Acquire > Triage Package. In the Acquire Triage Package dialog box, specify the triage type and other information. Click Acquire.
To download a specific artifact, click the Artifacts tab, and then select Download Artifact in the menu at the end of the row.
Note
See the Endpoint Security (HX) Server User Guide for more information.