After identifying a suspicious object that you want to investigate, you can collect the network analysis package (including an investigation package, a PCAP file, and a selected file detected by the network appliance) in a password-protected archive and download the file from the Response Management app.
This task is supported by the following services:
-
Deep Discovery Inspector
![]() |
WARNINGDownloading suspicious samples may potentially harm your endpoint.
Ensure that you take the necessary precautions before continuing. Trend Vision One automatically stores the
collected samples in a password-protected ZIP archive.
|
![]() |
ImportantTo execute the Collect Network Analysis Package task, you must first enable the
Virtual Analyzer and packet capture function in Deep
Discovery Inspector.
|
Procedure
- After identifying the object that you want to collect, access the context or
response menu and click Collect Network Analysis
Package.The Collect Network Analysis Package Task screen appears.
- Specify a Description for the response or event.
- Click Create.Trend Vision One creates the task and displays the current task status in Response Management.
- Monitor the task status.
- Open Response Management.
- (Optional) Locate the task using the Search field or by selecting Collect Network Analysis Package from the Action drop-down list.
- View the task status.
-
In progress (
): Trend Vision One sent the command and is waiting for a response.
-
Successful (
): The command was successfully executed.
-
Partially successful (
): The collection of one or more files was unsuccessful
-
Unsuccessful (
): An error or time-out occurred when attempting to send the command to the managing server, the Security Agent is offline for more than 12 hours, or the command execution timed out.
-
- Download the network analysis package.
- In the Response Management app, find the
Collect Network Analysis Package task and
click the options button (
) at the right of the row.
- Click Download Package.
- On the screen that appears, record the password for the archived sample.
- Click OK to download the file.
Tip
Use an external decompression program (such as 7-zip) to extract the file contents.
- In the Response Management app, find the
Collect Network Analysis Package task and
click the options button (