Events View - File Tab

The File tab is in the Event Details panel. Here you can safely view a list of files and download one or more files in an event.

Workflow

netwitness_wkflow-emailrecon.png

What do you want to do?

User Role I want to ... Show me how

Incident Responder or Threat Hunter

review detections and signals seen in my environment

NetWitness Platform Getting Started Guide

Incident Responder

review critical incidents or alerts

NetWitness Respond User Guide

Threat Hunter query a service, metadata, and time range

Begin an Investigation in the Events View

Begin an Investigation in the Navigate or Legacy Events View

Threat Hunter

view metadata

Filter Results in the Navigate View

Drill into Metadata in the Events View

Threat Hunter

view sequential events

Filter Results in the Events View

Filter Results in the Legacy Events View

Threat Hunter

reconstruct and analyze an event

Examine Event Details in the Events View

Reconstruct an Event in the Legacy Events View

Threat Hunter examine files and associated hosts*

Download Data in the Events View

Export or Print a Drill Point in the Navigate View

Export Events in the Legacy Events View

Threat Hunter perform lookups

Look Up Additional Context for Results

Launch a Lookup of a Meta Key

Threat Hunter create an incident or add to an incident

Add Events to an Incident in the Legacy Events View

Add Events to an Incident in the Events View

Threat Hunter

add a meta value to a Context Hub list

Look Up Additional Context for Results

*You can perform this task in the current view.

Related Topics

Quick Look

The File panel displays a list of files associated with a network event. You can download files in this view.

Below is an example of the File panel.

122_file_reconstruct_warning_1122.png

Feature Description
Download Files button Click to download one or more selected files.
Event Header The Event Header displays summary information for the network event that contains the files.
Files List Scrollable list of associated files that you can select and download.
VirusTotal Lookup Click to perform a search on MD5, SHA1, or SHA256.