Hosts View - Files TabHosts View - Files Tab
Note: The information in this topic applies to NetWitness Version 11.1 and later.
The Files tab displays all files on the host including the files deleted within last 30 days. To access this tab, select a host from the Hosts view and click the Files tab. By default, it displays 100 files. To display more files, click Load More at the bottom of the page.
Workflow
What do you want to do?
User Role | I want to ... | Show me how |
---|---|---|
Threat Hunter | review hosts with highest risk score* | |
Threat Hunter | analyze hosts* | Investigating Hosts |
Threat Hunter | perform adhoc scan* | |
Threat Hunter | review host details | |
Threat Hunter | search files on host* | Search Files on Host |
Threat Hunter | analyze processes | |
Threat Hunter | review reported anomalies | |
Threat Hunter | analyze risky users | Analyzing Risky Users |
Threat Hunter |
analyze events* |
|
Threat Hunter | download files for deeper analysis* | Analyzing Downloaded Files |
Threat Hunter | perform external lookups* | Launch an External Lookup for a File |
Threat Hunter | change file status or remediate* | Changing File Status or Remediate |
Threat Hunter |
filter files* |
|
Threat Hunter | isolate host from network* | Isolating Hosts from Network |
Threat Hunter | download MFT*, system dump, or process dump* | Performing Host Forensics |
*You can perform this task in the current view.
Related Topics
- Focusing on Endpoint Analysis
- Investigating Hosts
- Analyzing Downloaded Files
- Changing File Status or Remediate
- Analyzing Events
- Performing Host Forensics
- Isolating Hosts from Network
Quick Look
Below is an example of the Files tab:
1 |
Agent and Scan Details. You can view the following agent and scan details of the selected host: Host name - Name of the host. For example, WIN-ABC. Risk score - Risk score of the host. Operating System - Operating system on which the agent is running (Linux, Windows, or Mac). Agent Scan Status - Current status of the scan - Idle, Scanning, Starting Scan, or Stopping Scan. For more information, see Scan Hosts. Agent Last Seen - Time when the agent last communicated with the Endpoint server. Agent Version - Version of the agent. For example, 11.3.0.0. More - Provides options to:
Snapshot Time - Lists scanned time stamps. To view the scan history, you can select the snapshot time from the drop-down menu. |
2 |
Actions in the toolbar: Change File Status - Provides capabilities to manage suspect and legitimate files and block malicious or infected file to prevent future execution of the file on any host. For more information, see Changing File Status or Remediate. Analyze Events - Lets you investigate a particular host, IP address, username, filename, or hash to get the entire context of the activity. For more information, see Analyzing Events. More Actions - Provides options to:
Note: You can perform some of the above actions from the right-click context menu. |
3 | Search files on host. Lets you search the files on the host (file name, file path, and SHA-256 checksum). For more information, see Search Files on Host. |
4 | All Files Available on Host - Lists all files (reported as part of scan and tracking) on the host. By default, All Files Available on Host toggle is enabled for Windows and Mac. |
5 | Details Panel - Displays information, such as filename, local risk score, global risk score, on hosts, reputation status, file status, package details and others. |
6 | Show/Hide Right Panel - Displays the following properties in the right panel:
|
7 | Clicking a filename lets you navigate to the Files view for further analysis. |
8 |
Filter Files. You can filter files by selecting the options in the Filters panel and create filters. Note: In the Deleted column, a trash icon appears next to the deleted file. The Deleted column is not displayed if you disable All Files Available On Host. For more information, see Filter Host Details. |
9 | Settings Menu. You can set Hosts view preferences by selecting columns from the Settings menu. For more information, see Set Hosts Preference. |