After identifying a suspicious object that you want to investigate, you can collect the network analysis package (including an investigation package, a PCAP file, and a selected file detected by the network appliance) in a password-protected archive and download the file from the Response Management app.
Downloading suspicious samples may potentially harm your endpoint. Ensure that you take the necessary precautions before continuing. Trend Vision One automatically stores the collected samples in a password-protected ZIP archive.
To execute the Collect Network Analysis Package task, you must first enable the Virtual Analyzer and packet capture function in Deep Discovery Inspector.
The Collect Network Analysis Package Task screen appears.
Trend Vision One creates the task and displays the current command status on the Response Management app.
In progress... (): Trend Vision One sent the command
to the managing server and is waiting for a response
Successful (): The managing server successfully received
the command
Partially successful (): The collection of one or more files was
unsuccessful
Unsuccessful (): An error or time-out
occurred when attempting to send the command to the managing server, the Security
Agent is offline for more than 12 hours, or the command execution timed out
Use an external decompression program (such as 7-zip) to extract the file contents.