Views:

A one-time investigation is an investigation that runs only once.

To view the results and monitor the progress of one-time investigations, go to Response > Detailed Investigation, and click the One Time Investigation tab.

The following details are available for review.

Column

Description

Status

Current state of the investigation

Progress

Percentage of completion of the investigation

Name

User-defined name that identifies the investigation

Click to view the investigation results.

Method

Method used by the investigation

Criteria

  • File name of the OpenIOC or YARA rule file

  • User-defined registry value

Matched Endpoints

Number of endpoints that contain an object matching the specified criteria

Target Endpoints

Total number of selected endpoints for investigation

Click to view more details about the selected endpoints.

Note:

The Target Endpoints screen may not show all endpoints selected for the investigation. A user can only view endpoints where he has been granted sufficient access rights.

Started

Date and time when the investigation started

Elapsed

Time elapsed since the start of the investigation

Creator

User who created the investigation

Click New Investigation to start a new investigation.

Select at least one investigation to enable the following options:

  • Stop: Cancels the investigation. Stopped investigations cannot be resumed.

  • Delete: Stops the investigation, and then removes the investigation from the list. Removed investigations cannot be recovered.