During the investigation, when you know the specific endpoint impacted due to a malicious activity, you can use the Trellix EDR Device Search capability to search for malicious artifacts on a single endpoint. The results shown are categorized into different artifacts such as processes, CLI & script content, executable files, network connections, etc. with the number of records present in the endpoint. This level of customized information related to the impacted endpoint helps SOC in the investigation.
You can search for an endpoint data by typing an endpoint name and perform a search for the activities in a specific time frame.
Log on to Trellix EDR.
Navigate to Menu → Device Search.
Search for an endpoint using Device Name, Agent ID, or GUID from the Search drop-down menu.
From the Detection window drop-down list, select the time frame in which you want to view the historical data. The default Detection window is 24h before - 24h after.
Note
If you select Custom in Time Range, you can manually choose year, month, day, and hour.
Filter your search results using the Include and Exclude filters. You can type keywords that you want to include or exclude in your search query.
Starts with and Exact filters search over the whole retention period.
Contains filter limits the search to a 24-hours period.
Not all columns in each bucket are searchable.
On the grid, you can hover over the column headers and click on the menu icon to perform these activities:
Note
The EDRF Client generates a unique Agent ID for each endpoint. The interface displays the Agent ID only when the endpoint runs on the EDRF Client and is connected to the Endpoint Security (HX) server. The field remains blank if the endpoint is disconnected.
Pin Column — Pin a column to the left or right. You can click No Pin to unpin a column.
Autosize This Column — Auto size a particular column
Autosize All Columns — Auto size all columns
Group by Trace time — Group columns by trace time. You can use Un-Group by Trace time to un-group the Trace time column.
By default, all the columns are displayed on the grid and you can group and ungroup all columns.
Reset Columns — Reset columns to the default view.
Filter... — Filter results within a column.
The available logical operators and options for the Date type of columns:
Options — Equals, Greater than, Less than, Not equal, In range
Logical operators — AND and OR
The available options and logical operators for the String type of columns:
Options — Contains, Not Contains, Equals, Not equal, Starts with, and Ends with
Logical operators — AND and OR
The available options and logical operators for the Numerical type of columns:
Options — Equals, Greater than, Less than, Not equal, In range, Greater than or equals, and Less than or equals
Logical operators — AND and OR
The available options and logical operators for the Boolean type of columns:
Options – Equals and Not equals
Search... — Search and select column headers to add multiple columns to the grid.
You can add or remove columns to the grid using Search....
For more details about filtering operators and sorting options in Device Search and Historical Search, see KB96644.
You can also perform these activities on the grid:
Sort columns in ascending or descending order
Drag columns to set row groups
Move or rearrange columns to the left or right
To display specific data, use the buckets displayed under Artifacts:
Processes — Lists the processes that are running in the device. A new Process Integrity column is now implemented that rates the current process's integrity.
CLI & Script Content — Lists information about PowerShell commands or script blocks executed in a PowerShell console or script.
Important
The default events collected can be reduced through filtering according to customer value through content changes. To enable the collection of all events without filters, there is a new configuration option:
Log on to Trellix EDR as administrator.
Go to the Configuration page.
Under Finetune configuration, select Customize data to collect.
Select the Enable verbose collection of CLI & Script content checkbox.
Enter your Device and Period, then click Save.
Executable Files — Lists the executable files on the device. The Activity column indicates when a file is read, moved, executed, modified, deleted, or changed. File extension and EPP related columns are neither sortable nor searchable by Include and Exclude filters.
From the results displayed on the Process Name column, you can hover over a process name and copy the absolute path to search using the Include filter. The result might include other traces for which the absolute path matched with different fields.
Note
When an executable file is run, an icon appears next to the file name with information generated by EPP: action taken, reason, and endpoint product that carried out the action.
Non Executable Files — Lists file events that are not Portable Executables, scripts, or file archives. File extension column is neither sortable nor searchable by Include and Exclude filters.
Archived Files — Lists the files that were archived. For example, .zip, .rar files. File extension and EPP related columns are neither sortable nor searchable by Include and Exclude filters.
Scripts — Lists the scripts written on the device. File extension and EPP related columns are neither sortable nor searchable by Include and Exclude filters.
Dual-Intent Tools — Lists the processes executed through hacking or administration tools installed on the device. PowerShell is an example of an administrative tool.
Services — Lists the Windows and Linux services added, removed, or modified in the device. Service Type and Start Type columns are neither sortable nor searchable by Include and Exclude filters.
Network Connections — Lists the number, type, direction (inbound or outbound), and port of network connections on that device. You can also see network information related to Layer 7 such as URL, Verb, Protocol, and DNSs.
Important
The source IP address in HTTP traffic can be retrieved for certain Network/Trace events but may be unavailable for others. The field will be empty if the IP address cannot be retrieved.
When the IP address can be retrieved
Network/Trace events operate at OSI Layer 4 or below.
The protocol uses the WinSock Windows API, which operates at OSI Layer 4.
When the IP address cannot be retrieved
Network/Trace events operate at OSI Layer 5 or above.
The data packet received at the OSI layer is incomplete.
The system uses NAT or a proxy.
Note
Certain events for network connections on ports 80 and 443 are not displayed by default. To view all events related to ports 80 and 443, you can use the Customize data to collect option in the Configuration menu. For more information, see the Trellix EDR Installation Guide.
Windows Registry Keys — Lists information related to Windows registry key values in a device monitored by Trellix EDR.
Note
An icon appears next to the registry key name with information generated by EPP: action taken, reason, and endpoint product that carried out the action.
Scheduled Tasks — Lists the scheduled tasks on Windows that were changed.
DNS Requests — Lists the DNS requests made by the device.
User Logon Activities — Displays frequency of the user logon sessions on the device.
Loaded DLLs — Lists the DLLs that are loaded by processes. By default not all DLLs are sent to the cloud, but you can set the Trellix EDR policy (from ePO - On-prem or ePO - SaaS) to send all DLLs loaded by monitored processes. In the Loaded Modules column, you can click the Show all DLLs link to display the complete list of modules.
User Account Activities — Lists the account created date, account type, target account name, and target domain of the user.
API calls — Lists information about Windows APIs used by processes monitored by Trellix EDR.
WMI Activity — Lists the activities performed by Windows Management Instrumentation (WMI) service for messages that Trellix EDR captures. Registry Type column is neither sortable nor searchable by Include and Exclude filters.
Endpoint Protection Activity — Lists the EPP activity triggered on Windows device. The following information is displayed:
Date
Process ID
Action executed
Reason
Endpoint Product
Detections and Alerts — Lists specific behaviors detected in the environment with different levels of confidence. Confidence is assigned by a detection engine based on the severity of a threat.
Alerts — Lists specific behaviors detected in the environment with high confidence alerts.
Analysis Options for Artifacts — Each artifact under Ask Wise functionality in Device Search dashboard comes with a set of analysis options for performing detailed threat analysis. By default, the following analysis options are available for each artifact:
Brief me on related MITRE TTPs
Tell me about related breaches
Generate a knowledge graph
Provide more detail
Suggest some recommended actions
Draft an email
For a select number of artifacts, additional predefined analysis options are provided alongside these default options as mentioned below.
Artifact
Analysis options
Processes
Analyze Process, Analyze Script Content
CLI & Script Content
Analyze Process, Analyze Script Content
Executable Files
Analyze Files
Non-Executable Files
Analyze Files
Archived Files
Analyze Files
Scripts
Analyze Files
Network Connections
Analyze Network Connections
Windows Registry Keys
Analyze Registry Keys
DNS Requests
Analyze Network Connections
Loaded DLLs
Analyze Loaded DLLs
API Calls
Analyze Windows APIs
Each artifact category includes a predefined set of columns. This list describes the columns used in the Device Search and Historical Search dashboards. For details, see Device Search and Historical Search column reference.
Click Export All to export data for the selected artifact in .CSV file format.
Note
The maximum data you can export is 100K results or file size with 500 MB, whichever is lesser for all artifacts except Detection & Alerts and Alerts. For Detection & Alerts and Alerts, you can export data up to 10K results.
You can use the historical data to analyze a threat by tracing its behavior from the past 4 hours to the maximum retention time.