Reconstructing sessions using PCAP files from a PX Series appliance

Prev Next

The NDR Series appliance pulls PCAP artifacts directly from the PX Series appliance.

Note

The NDR can extract files up to 1 gigabyte. The NDR hexadecimal output from the session reconstruction will only show the first 10 megabytes and it will discard the remaining portion.

After the artifact is extracted from the PCAP, you can download the file as a password-protected .zip file or push it to the AX Series appliance to see if it is malicious.

Prerequisites

  • Connected PX appliance running 4.5.0 software version

Reconstructing a session

The NDR extracts files from the PCAP and generates the hexadecimal ASCII view of the packets. You can search for certain strings or hex patterns within the PCAP. The default password is password.

You can reconstruct the following sessions:

  • SMTP

  • POP3

  • IMAP

  • FTP

  • SMB

  • HTTP

To reconstruct a session in the Web UI:

Important

You must have a PX Series appliance deployed in your network in order to pivot to the PX or reconstruct PCAP for alerts generated from other Trellix appliances, including NX, EX, HX, and CM Series.

  1. Click Main_menu.png and from INVESTIGATION, select Search.

  2. Go to an event table on the dashboard.

  3. Select the sessions that you want to reconstruct by checking the box on the left side of the table.

  4. Select the beaker icon at the top of the event table to reconstruct the PCAP.

  5. (Optional) To download all the artifacts simultaneously, click DOWNLOAD ALL ARTIFACTS.

    The DOWNLOAD ALL ARTIFACTS button is enabled if there is at least one artifact available.