After identifying a suspicious file object that you want to investigate in your local environment, you can collect the file in a password-protected archive and download the file from the Response Management app.
Downloading suspicious samples may potentially harm your endpoint. Ensure that you take the necessary precautions before continuing. Trend Vision One automatically stores the collected samples in a password-protected ZIP archive.
The Collect File Task screen appears.
Trend Vision One creates the task and displays the current command status on the Response Management app.
Pending approval () (if applicable): The automated response task
was created on the Workbench app and is waiting for
approval
Rejected () (if applicable): The automated response task
created on the Workbench app was rejected
In progress... (): Trend Vision One sent the command
to the managing server and is waiting for a response
Queued (): The managing server queued the command
because the Security Agent was offline
Successful (): The managing server successfully received
the command
Unsuccessful (): An error or time-out
occurred when attempting to send the command to the managing server, the Security
Agent is offline for more than 12 hours, or the command execution timed out
Downloading suspicious samples may potentially harm your endpoint. Ensure that you take the necessary precautions before continuing. Trend Vision One automatically stores the collected samples in a password-protected ZIP archive.
Use an external decompression program (such as 7-zip) to extract the file contents.