Views:
A one-time investigation is an investigation that runs only once.
To view the results and monitor the progress of one-time investigations, go to ResponseLive Investigation, and click the One Time Investigation tab.
The following details are available for review.
Column
Description
Status
Current state of the investigation
Progress
Percentage of completion of the investigation
Name
User-defined name that identifies the investigation
Click to view the investigation results.
Method
Method used by the investigation
Criteria
  • File name of the OpenIOC or YARA rule file
  • User-defined registry value
Matched Endpoints
Number of endpoints that contain an object matching the specified criteria
Target Endpoints
Total number of selected endpoints for investigation
Click to view more details about the selected endpoints.
Note
Note
The Target Endpoints screen may not show all endpoints selected for the investigation. A user can only view endpoints where he has been granted sufficient access rights.
Started
Date and time when the investigation started
Elapsed
Time elapsed since the start of the investigation
Creator
User who created the investigation
Click New Investigation to start a new investigation.
Select at least one investigation to enable the following options:
  • Stop: Cancels the investigation. Stopped investigations cannot be resumed.
  • Delete: Stops the investigation, and then removes the investigation from the list. Removed investigations cannot be recovered.