Analysis and documentation

Analysis and documentation

Forensic investigations include additional data for analysis and documentation purposes.

  • Issues
  • Forensics Timeline
  • Key Assets & Artifacts

Review Issues

The issues table displays all the collections within the investigation that has identified suspicious or malicious activity within the forensics data sets.

Refer to Overview of the Issues page for descriptions of the table fields.

The following actions are available for a selected alert.

  • Change status
  • Change severity
  • Investigate causality chain
  • Run playbook
  • Manage alerts

Investigation timeline

The Timeline page enables you to view the list of forensic artifacts that were tagged. The tags display details of the forensic data collected from the endpoints.

The Timeline table displays the following fields:

FieldDescription
HostnameName of the host machine.
TimestampTimestamp associated with the artifact.
TypeForensic artifact of which a tag was added.
DescriptionName of the timestamp field.
Tags

There are three default tags to choose from.

  • legitimate
  • malicious
  • suspicious

You can also create your own tags.

UserUser account associated with the forensic artifact.
DataData summary for the tagged item.
Mitre Att&ck TacticDisplays the type of MITRE ATT&CK tactic of the tagged item.
Mitre Att&ck TechniqueDisplays the type of MITRE ATT&CK technique of the tagged item.
NotesDisplays notes entered by the user.
  1. Edit a timeline entry

    You can edit a tag of an artifact in the Timeline table.

    1. Locate the relevant item to update the tag.
    2. Right-click and select Edit timeline entry.
    3. In Edit timeline entry, update the information as required and then click Save to update the changes.
  2. Clear a timeline entry

    You can remove a tag from the artifact in the Timeline table.

    1. Locate the relevant item to remove the tag.
    2. Right-click and select Clear timeline entry. The tag is removed from the artifact and the row is removed from the Timeline table.

Key assets & artifacts

Key assets & artifacts are automatically created based on the tagged data from the investigation timeline of the investigation and are divided among the categories:

  • Data Access: Displays all the items that have been tagged in the File Access tables.

The following table for Endpoints displays the endpoints that have at least one or more items tagged:

FieldDescription
Endpoint NameName of the endpoint.
Endpoint Type

Displays the endpoint type:

  • Mobile
  • Server
  • Workstation
  • Kubernetes Node
Endpoint Status

Displays the status of the endpoint:

  • Connected
  • Connected Lost
  • Deleted
  • Disconnected
  • Uninstalled
  • VDI Pending Login
  • Forensics Offline
  • Partial Registration
Earliest ActivityTimestamp of the earliest tagged item in the incident timeline for the endpoint.
Latest ActivityTimestamp of the last tagged item in the incident timeline for the endpoint.
IP AddressList of associated IP addresses.
IPv6 AddressList of associated IPv6 addresses.
First SeenTimestamp of first seen.
Last SeenTimestamp of last seen.
Endpoint Isolated

Displays the status of endpoint isolation:

  • Pending Isolation Cancellation
  • Pending Isolation
  • Isolated
  • Not Isolated
Isolation DateIsolation date of the endpoint.

The following table for Malware shows all the items that have been tagged in the Process Execution or Persistence tables.

FieldDescription
File NameName of the artifact collected from the endpoint.
PathExecutable path.
TagsAssigned tags to the artifact.
SHA256SHA256 value of the executable file.
VerdictsWildFire verdicts.
UserUser name of the person who ran the process.
Mitre ATT&CK TacticTactic selected during tagging.
Mitre ATT&CK TechniqueTechnique selected during tagging.
Platform

Operating system of the endpoint:

  • Windows
  • macOS
  • Linux
  • Android
CreatedCreation timestamp of the file accessed.
AccessedAccessed timestamp of the file accessed.
ModifiedModified timestamp of the file accessed.

The following table for Users displays any artifact data with a non-null user field that has been tagged.

FieldDescription
UsernameUsername of the person who ran the process.
DomainDomain of the user's computer.
ID

Indicates the operating system:

  • UID for macOS and Linux
  • SID for Windows
Earliest ActivityTimestamp of the earliest tagged item in the Incident Timeline for the user.
Latest ActivityTimestamp of the last tagged item in the Incident Timeline for the user.

The following table for Network Indicators displays the event logs with the IP addresses that have been tagged.

FieldDescription
IndicatorData field that was tagged.
Type
  • IP Address
  • Hostname
  • URL
CountryGeolocation data for IP addresses.
FlagFlag of the geolocated country.
OrganizationOrganization associated with the IP address.

The following table for Data Access displays all the items that have been tagged in the File Access tables.

FieldDescription
PathPath of the accessed file.
UserUser name of the person who accessed the file.
CreatedCreation timestamp of the file accessed.
AccessedAccessed timestamp of the file accessed.
ModifiedModified timestamp of the file accessed.
SizeSize of the file.