When a potential threat is detected, you can hunt for potentially malicious processes of the same threat that are dormant in your endpoints but likely to be executed. This allows you to quickly detect and respond to threats before the attack occurs.
Log on to Trellix EDR as administrator.
Select Menu → Monitoring.
In the Threats by Ranking / Threats by Time pane, select a threat.
Tip
Use the Search filter in the Threats by Ranking / Threats by Time to find threats by name or ID.
In the Process Activity pane, select Sequential view.
Click an event to display the details and investigate the suspicious activity.
In the Event details pane, under Process info, click the Name of the process, and select Find process on all devices.
The Real-time Search dashboard opens in a new tab and an automatic query is generated. You can see a list of all the devices where the process is found but has not been executed yet.
Select one or more devices, go to Actions and select the one you want to take to contain the threat or investigate it further.