Investigating Details About a Detection Parent topic

Procedure

  1. Search for the detection.
  2. Click the plus sign next to the detection in the table.
    detections_all_detai.png
    The table row expands to display detailed information.
    detections_all_detai_001.png
  3. Examine the detection details.
  4. (Optional) If a threat name is displayed in the Threat name field, click on the threat name to open the ThreatConnect page where you can view detailed information about that threat.
  5. (Optional) If the value displayed in the Detected by field is Suspicious Objects Analysis (Virtual Analyzer) or Suspicious Objects Filter (Virtual Analyzer), you can display or download the Virtual Analyzer report and download the Virtual Analyzer investigation package for a specified detection.
    1. Go to the Virtual Analyzer Report section at the bottom of the details page.
      investigative_packag.png
    2. Open the Virtual Analyzer report in HTML or PDF format.
    3. Download the Virtual Analyzer investigation package.