The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Perform Network Forensics

Prev Next

You can perform the Network Forensics for either the source endpoint or the destination endpoint. This analyzes and provides information about the endpoints.

Note

Network Forensics is not applicable for the Central Manager.

Task

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.
  2. Select the alert whose IP to which you want to perform forensics.
  3. Click Other Actions, and select Perform Network Forensics. Click the endpoint IP for which you want to perform forensics.
    The Network Forensics page opens. The IP address is populated based on the endpoint selected to perform forensics.
    Network Forensics


  4. Select the date and time. Use the time to view endpoint behavior before and after an attack.
  5. Click Analyze.
    Detailed information about the endpoint is displayed.

    Click the icon to close the network forensics page.

    For more information on network forensics, see the Network Threat Behavior Analysis Product Guide.