Process trace

Prev Next

Process trace displays details for processes executed on your endpoints in graph format.

Process trace can be accessed from the following locations:

  • Campaign > View Details > Your Environment > Your ENS Devices > All Impacted Devices

  • Devices > Events

  • Search results -> Events

If a trace is available for an event, a graph icon is enabled. A graph icon does not appear where no trace data is available.

GUID-1E198DBE-2DC5-4839-A2AE-A6FC8858E3F6-low.png

Graph layout and toolbars

The graph can be viewed in two different layout formats:

  • Standard (default layout) - nodes are connected in the order in which they were created.

  • Sequential - nodes are connected in the order in which the process was executed. Sequential layout displays a time bar to filter the graph by a selected time range.

Users can perform the following actions using the toolbar:

  • Zoom in, zoom out, reset, and use full screen mode for improved visibility.

  • Download the graph in high-resolution PNG format.

GUID-66FC39A4-2B9B-45B4-AEFB-566FC2366F94-low.png

Nodes

Node details and pivots are shown when clicked.

Nodes are grouped and sub-grouped based on categories and subcategories. For processes, nodes are grouped where process activity occurs more than once. Nodes are further sub-grouped based on additional activities including read file, write file, and more.

More prominent nodes with multiple incoming and outgoing connections are excluded from the grouping.

Nodes

Group/Subgroup nodes

Edges

ePO

Files Created

Artifacts dropped

BPS

File Paths

Has device

Device Name

IPs/Domains

Observed file

Agent Guild - <agent GUID>

Registries

Observed URL

Campaign Name

File Hashes

Dropped by

File path

Hidden Files Created

Drops file

Mutex

AMSI Buffers

Downloaded from URL

File Hash MD5

Registries Set

Downloads file

Process

Directories Created

Is a threat

Registries Created

Has domain

Files Read

Domain of

Registries Deleted

Is associated with

Files Written

Downloaded from domain

Files Deleted

Mutex

Files Modified

Is associated with campaign

Files Moved

Create Registry Key

Files Copied

Set Registry Value

Directories Deleted

Delete Registry Key

TCP Connections

Create Process

TCP Connections Accepted

Exit Process

UDP Connections

Inject DLL

UDP Connections Received

Loads DLL

DLLs Injected

Create File

DLLs Loaded

Write File

Mutexes

Delete File

MD5s Dropped

Read File

IPs Connected

Modify File

Domains Connected

Move File

Downloaded URL

Copy File

Create Directory

Delete Directory

Create Hidden File

Connect TCP

Accept TCP

Send UDP

Receive UDP

Create Registry Key

Set Registry Value

Delete Registry Key

Downloads File

Create Pre-Process

AMSI Buffer Scan

File-MD5

Manages

Uses Technique

Involves

Mitigation

Has Sighting

Observed in

Reported in

Belongs to

Associated with

Uses Tool

Uses Malware

Uses

File Hashes Dropped

File Operations

Network Operations

Registry Operations

Operations

Create Remote Thread

File Hash Dropped

Orphan Thread

Node

Details Shown

Process/Exit Process

  • Path

  • Activity

  • Timestamp

  • Command line arguments

  • MD5

  • MD5 details

File Path

  • Path

  • Activity

  • Timestamp

  • Command line arguments

  • MD5

  • MD5 details

File Hash MD5

  • Hash value

  • Activity

  • SHA256

  • SHA1

  • MD5

  • File Size

  • First Seen

  • Classification Name

  • Classification Type

  • Category

  • Insights Type

  • Comments

  • Prevalent in Country

  • Prevalent in Sector

  • Lethality

  • Determinism

  • Pivot to IOC Details page by clicking View this IOC button

  • Pivot toTrellix EDR button

Mutex

  • Mutex

  • Activity

  • Timestamp

Campaign

  • Name

  • Description

  • Associated IoCs

  • Severity

  • Exposed devices

  • Devices with Insufficient Coverage

  • Last Detected

  • Labels

  • Pivot to Campaign Details page by clicking the View this Campaign button

Device

  • System name

  • IP address

  • Users

  • Tags

  • Operating System

  • Go to System Tree button

IP/Domain

  • IP/Domain

  • Category

  • Insights Type

  • Comments

  • Lethality

  • Determinism

  • Prevalent in Sectors

  • Prevalent in Countries

  • Pivot to IOC button

Groups/Subgroups

Double clicking on a group or subgroup expands and displays all associated nodes

ePO, NSP, NSM, BPS

No details

MITRE related nodes

  • MITRE Category

  • Name

  • Description