Process Tracker Module

Process Tracker is an HX Innovation Architecture module designed to recognize unique file executions on an endpoint and report these executions to HX. If enrichment is enabled, all process execution events will be enriched utilizing the standard Enricher workflow. If alerting is enabled, all events deemed malicious by Enricher will throw a generic alert of type “PRO”. Further if auto-triage is enabled, standard triage collection will initiate automatically on the endpoint associated to the alert.

Process Tracker will cache the execution events for a configurable amount of time. These events are available to be analyzed within the user interface that provides a grid view which can be searched. Custom filters can be configured and saved. All data within the grid is accessible via REST API to integrate with your custom solution. Real time access to events and alerts is also available via the HX message bus.

This general availability release of Process Tracker is supported on Endpoint Security 5.0 with xAgent 32.

This is a replacement to the technical preview release of Process Tracker. As such, the technical preview is not upgradeable. You must uninstall the technical preview, then install this general availability release.

Authentication RequiredDownloading this app requires a FireEye subscription to use and is only accessible for FireEye users with an active FireEye Support account. If you already have an account, please . Otherwise, please Request Support Access or Contact Sales to learn more about becoming a FireEye customer.

Module Info

Version:1.2.4
Last Updated:May 15, 2020
Platform:Linux, macOS, Windows
Requirements:FireEye Endpoint Security 5.0 with xAgent 32+
Size:30.16 MB
MD5:FC4DFD20075329B68AB4B4B854BBB069
SHA1:6E585F8E2891B256CCD61A377108624F2E9501FD
SHA256:25474654F6E8B26A9C88D247C5F39FB187B01A4368B63CDAC44621F5AADB80E8

Similar Apps

Endpoint Security Module
Endpoint Security Module
Endpoint Security Module
Endpoint Security Module