The NDR Series appliance pulls PCAP artifacts directly from the PX Series appliance.
Note
The NDR can extract files up to 1 gigabyte. The NDR hexadecimal output from the session reconstruction will only show the first 10 megabytes and it will discard the remaining portion.
After the artifact is extracted from the PCAP, you can download the file as a password-protected .zip file or push it to the AX Series appliance to see if it is malicious.
Prerequisites
Connected PX appliance running 4.5.0 software version
Reconstructing a session
The NDR extracts files from the PCAP and generates the hexadecimal ASCII view of the packets. You can search for certain strings or hex patterns within the PCAP. The default password is password.
You can reconstruct the following sessions:
SMTP
POP3
IMAP
FTP
SMB
HTTP
Important
You must have a PX Series appliance deployed in your network in order to pivot to the PX or reconstruct PCAP for alerts generated from other Trellix appliances, including NX, EX, HX, and CM Series.
Click
and from INVESTIGATION, select Search.Go to an event table on the dashboard.
Select the sessions that you want to reconstruct by checking the box on the left side of the table.
Select the beaker icon at the top of the event table to reconstruct the PCAP.
(Optional) To download all the artifacts simultaneously, click DOWNLOAD ALL ARTIFACTS.
The DOWNLOAD ALL ARTIFACTS button is enabled if there is at least one artifact available.