After identifying a suspicious object that you want to investigate, you can collect the network analysis package (including an investigation package, a PCAP file, and a selected file detected by the network appliance) in a password-protected archive and download the file from the Response Management app.
This task is supported by the following services:
-
Deep Discovery Inspector
WARNINGDownloading suspicious samples may potentially harm your endpoint.
Ensure that you take the necessary precautions before continuing. Trend Vision One automatically stores the
collected samples in a password-protected ZIP archive.
|
ImportantTo execute the Collect Network Analysis Package task, you must first enable the
Virtual Analyzer and packet capture function in Deep
Discovery Inspector.
|
Procedure
- After identifying the object that you want to collect, access the context or
response menu and click Collect Network Analysis
Package.The Collect Network Analysis Package Task screen appears.
- Specify a Description for the response or event.
- Click Create.Trend Vision One creates the task and displays the current task status in Response Management.
- Monitor the task status.
- Open Response Management.
- (Optional) Locate the task using the Search field or by selecting Collect Network Analysis Package from the Action drop-down list.
- View the task status.
-
In progress (): Trend Vision One sent the command and is waiting for a response.
-
Successful (): The command was successfully executed.
-
Partially successful (): The collection of one or more files was unsuccessful
-
Unsuccessful (): An error or time-out occurred when attempting to send the command to the managing server, the Security Agent is offline for more than 12 hours, or the command execution timed out.
-
- Download the network analysis package.
- In the Response Management app, find the Collect Network Analysis Package task and click the options button () at the right of the row.
- Click Download Package.
- On the screen that appears, record the password for the archived sample.
- Click OK to download the file.
Tip
Use an external decompression program (such as 7-zip) to extract the file contents.