Views:

After identifying a suspicious object that you want to investigate, you can collect the network analysis package (including an investigation package, a PCAP file, and a selected file detected by the network appliance) in a password-protected archive and download the file from the Response Management app.

This task is supported by the following services:
  • Deep Discovery Inspector
WARNING
WARNING
Downloading suspicious samples may potentially harm your endpoint. Ensure that you take the necessary precautions before continuing. Trend Vision One automatically stores the collected samples in a password-protected ZIP archive.
Important
Important
To execute the Collect Network Analysis Package task, you must first enable the Virtual Analyzer and packet capture function in Deep Discovery Inspector.

Procedure

  1. After identifying the object that you want to collect, access the context or response menu and click Collect Network Analysis Package.
    The Collect Network Analysis Package Task screen appears.
  2. Specify a Description for the response or event.
  3. Click Create.
    Trend Vision One creates the task and displays the current task status in Response Management.
  4. Monitor the task status.
    1. Open Response Management.
    2. (Optional) Locate the task using the Search field or by selecting Collect Network Analysis Package from the Action drop-down list.
    3. View the task status.
      • In progress (in_progress=GUID-A55897DB-3DEA-4F5C-B7F9-70B3D7FB9EDE=1=en-us=Low.jpg): Trend Vision One sent the command and is waiting for a response.
      • Successful (successful=GUID-1E31AD86-DE2E-48B5-85F7-7C78A3E8BB11=1=en-us=Low.jpg): The command was successfully executed.
      • Partially successful (partially_successful_icon=GUID-20230103030733.jpg): The collection of one or more files was unsuccessful
      • Unsuccessful (error=5cc21722-7ceb-480c-b9c2-a47d420cf1cc.jpg): An error or time-out occurred when attempting to send the command to the managing server, the Security Agent is offline for more than 12 hours, or the command execution timed out.
  5. Download the network analysis package.
    1. In the Response Management app, find the Collect Network Analysis Package task and click the options button (options_icon=GUID-408062FA-DA13-4ECA-81EB-31A5B68355A1=1=en-us=Low.jpg) at the right of the row.
    2. Click Download Package.
    3. On the screen that appears, record the password for the archived sample.
    4. Click OK to download the file.
      Tip
      Tip
      Use an external decompression program (such as 7-zip) to extract the file contents.