Create a Computer Investigation

Applies To: WatchGuard Advanced EPDR

To review the details of monitored and collected events that occurred on a computer on a specific day, you can start a computer investigation. You can start a computer investigation from the Computer Details page or from the Incident Details page. Go to the appropriate section:

Create a Computer Investigation from the Computer Details Page

Your operator role determines what you can see and do in WatchGuard Cloud. Your role must have the Access Advanced Telemetry permission to view or configure this feature. For more information, go to Manage WatchGuard Cloud Operators and Roles.

  1. In the Endpoint Security management UI, select Computers, then select a computer.
    The computer investigation for the selected computer opens.
  2. To create a computer investigation for another computer, on the Investigation page, click .
  3. Screenshot of Computer Investigation menu option

  4. Select Computer Investigation.
    The Investigate Computer page opens.
  5. Screenshot of Investigate Computer page

  6. Select the MUID or Computer Name check box and enter the unique identifier or Windows computer name in the text box.
  7. In the From text boxes, select the start date and time for the investigation.
  8. In the To text boxes, select the end date and time for the investigation.
  9. The date range cannot be greater than two days. You can select a date up to seven days prior.

  10. From the Time Zone drop-down list, select the time zone.
  11. Click OK.
    A computer investigation is created.

Create a Computer Investigation from the Incident Details Page

On the Incident Details page, you can start an investigation for the computer affected by the incident. For information on incident details, go to Review Incident Details in Endpoint Security.

Your operator role determines what you can see and do in WatchGuard Cloud. Your role must have the Access Advanced Telemetry permission to view or configure this feature. For more information, go to Manage WatchGuard Cloud Operators and Roles.

To start a computer investigation from the Incident Details page:

  1. In the Endpoint Security management UI, on the Security dashboard, select the Incidents Status tile.
    The Incidents list opens.

Screen shot of Incidents list, Endpoint Security

  1. From the Incidents list, click the name of the incident on a computer you want to investigate.
    The Incident Details page opens.

  1. Next to one of the signals in the list, click .
  2. Select Investigate Computer.
    The investigation opens within the Incident Details page.

  1. In the From text boxes, select the start date and time for the investigation.
  2. In the To text boxes, select the end date and time for the investigation.
  3. The date range cannot be greater than two days. You can select a date up to seven days prior.

  4. From the Tactics drop-down list, select the MITRE tactic you want to filter the list of events for.
  5. From the Techniques / Sub-techniques drop-down list, select the MITRE technique and sub-technique you want to filter the list of events for.
  6. Click Apply.
    Updated results show in the table. Select a row in the table to review more information on the event in the Details pane.
  7. To show the process tree in the Details pane, select the Process Tree check box. For more information, go to Process Tree.
  8. To show the incident timeline in the middle pane, select the Timeline check box. For more information, go to View Event Graphs.

About the Investigation Table

In a computer investigation, you can:

Related Topics

About the Advanced SQL Query Tool

Configure Verbose Mode