Endpoint: Hosts View - Process Tab

Document created by RSA Information Design and Development on Apr 11, 2019Last modified by RSA Information Design and Development on Jul 19, 2019
Version 4Show Document
  • View in full screen mode

Note: The information in this topic applies to RSA NetWitness® Platform Version 11.1 and later.

The Process panel provides a list of processes running on the host. To access this tab, select a host from the Hosts view and click the Process tab.


Workflow for Hosts

What do you want to do?

User RoleI want to ...Show me how
Threat Hunterreview hosts with highest risk score*

Analyze Hosts Using the Risk Score

Threat Hunteranalyze hosts* Investigating Hosts
Threat Hunterperform adhoc scan*

Scan Hosts

Threat Hunterreview host details

Analyze Host Details

Threat Huntersearch on snapshot*

Search on Snapshots

Threat Hunteranalyze processes*

Investigating a Process

Threat Hunterreview reported anomalies

Analyze Anomalies

Threat Hunteranalyze risky users Analyzing Risky Users

Threat Hunter

analyze events*

Analyzing Events

Threat Hunterdownload files for deeper analysis* Analyzing Downloaded Files
Threat Hunterperform external lookups*Launch an External Lookup for a File
Threat Hunterchange file status or remediate* Changing File Status or Remediate

*You can perform this task in the current view.

Related Topics

Quick Look

Below is an example of the Process tab:

Process tab


Agent and Scan Details. You can view the following agent and scan details of the selected host:

Host name - Name of the host. For example, WIN-ABC.

Risk score - Risk score of the host.

Operating System - Operating system on which the agent is running (Linux, Windows, or Mac).

Agent Scan Status - Current status of the scan - Idle, Scanning, Starting Scan, or Stopping Scan. For more information, see Scan Hosts.

Agent Last Seen - Time when the agent last communicated with the Endpoint server. indicates time when the roaming agent last communicated with the Endpoint server.

Agent Version - Version of the agent. For example,


Actions in the toolbar:
Snapshot Time - Lists scanned time stamps. To view the scan history, you select the snapshot time from the drop-down menu.
Start Scan - Starts a scan for the selected hosts. For more information, see Scan Hosts.
Export to JSON - Extracts host attributes and endpoint data to a JSON file of the selected snapshot. For more information, see Investigating Hosts.

Analyze Process - Lets you perform process analysis to investigate a particular process behavior, and understand the entire process event chain, process parent-child relationships, and all associated events. For more information, see Investigating a Process.

Change File Status - Provides capabilities to manage suspect and legitimate files and block malicious or infected file to prevent future execution of the file on any host. For more information, see Changing File Status or Remediate.

Analyze Events - Lets you investigate a particular host, IP address, username, filename, or hash to get the entire context of the activity. For more information, see Analyzing Events.

More - Provides options to:

  • Perform external lookups.
  • Download files to server, save a local copy, and analyze files for deeper analysis.

Note: You can perform some of the above actions from the right-click context menu.

3Search on Snapshots. Lets you search on all snapshots (file name, file path, and SHA-256 checksum). For more information, see Search on Snapshots.
4Toggle. Lets you toggle between List view and Tree view.
5Process panel - Displays process information, such as process name, local risk score, global risk score, active on, reputation status, file status, and others.

Show/Hide Right Panel - Displays the following properties of a process in the right panel:

  • File Details - Displays all properties of the selected process. It is grouped as follows:

    General - General information about the file, such as file name, entropy, size, and format.

    Signature - Provides signatory information.

    Hash - Hash type of the file (MD5, SHA1, and SHA256).

    Time - Time when the file was created, modified, or accessed.

    Location - Location of the file.

    Process - Details of the process, such as image size and PID.

    Image - Image details loaded by the process.

  • Local Risk Details - Displays the alerts associated with the local risk score, such as Critical, High, Medium and All.

Process Details

Clicking the process name displays the process details of a specific process as shown in the following figure:

Process details

Process NameName of the process. For example, server.exe.
PIDID of the process. For example, 492.

Path of the file associated with the process on the disk. For example, C:\Windows\System32.

Launch Arguments

Command line arguments passed to the process when it is launched. For example, -k LocalServiceNoNetwork.

  • List of loaded libraries for the selected process, such as DLLs (for Windows), Dylibs (for Mac), or .SO (for Linux).
  • List of autoruns (if configured).
  • List of image hooks and suspicious threads (for Windows).

You are here
Table of Contents > NetWitness Endpoint Reference Materials > Hosts View - Process Tab