Review and manage the software inventory for endpoints in your environment.
You can access this page by selecting:
Menu → Application Control → Inventory → By Applications (allows you to manage inventory for all endpoints in your environment)
Menu → Application Control → Inventory → By Systems → View (allows you to manage inventory for a single endpoint)
Menu → Systems → System Tree, select an endpoint, and select Actions → Application Control → View Inventory (allows you to manage inventory for the selected endpoint)
Option definitions
Option | Definition |
|---|
Views and Filters | Views — View the inventory details using these options: Application — Filters the inventory based on the applications installed on the endpoints. File Name — Displays files filtered by name. File SHA-1 — Searches for a file based on its SHA-1 value. File SHA-256 — Searches for a file based on its SHA-256 value. File MD5 — Searches for a file based on its MD5 value. Vendor — Filters the inventory based on the vendor name. Final Reputation — Filters the inventory and displays files based on the specified reputation value.
Search String — Enter a search string to filter the inventory details. The search string can be used with the available views. Search — Filters the displayed results based on the specified view and filter criteria. What's Final Reputation? — Opens a Trellix KnowledgeBase article that explains how the software determines final reputation for files or certificates.
|
Filters | Use these filters to view selected files. Add Saved Filter — Opens the Select View page where you can define a new filter. Use the available properties to define the filter. By default, the Hidden property is added to all new filters you define. The Hidden property is set to False allowing you to view only unhidden inventory items. If needed, you can edit the property value or remove the property from the filter.
Default View — Removes any applied filter and lists all unhidden inventory items. All Malicious Files — Displays all files where the Reputation value is Known Malicious, Most Likely Malicious, or Might be Malicious. This filter also displays all hidden files. Allowed Malicious Files — Displays all files where the Reputation value is Known Malicious, Most Likely Malicious, or Might be Malicious and that are allowed on your enterprise. This filter also displays all hidden files. Allowed Unknown Signed Files — Displays all files that are allowed in your enterprise, signed by a certificate, and with the Reputation value as Unknown. Allowed Unknown Unsigned Files — Displays all files that are allowed in your enterprise, not signed by a certificate, and with the Reputation value as Unknown. Banned Trusted Files — Displays all files banned in your enterprise and where the Reputation value is Known Trusted, Most Likely Trusted, or Might be Trusted. Files Discovered in Last Week — Displays all files that are added to your enterprise in the last week. When you upgrade to the 6.2.0 or later version of the Solidcore extension, no first seen information is available for the files. The time when you fetch the inventory after upgrade is recorded as the first seen information.
Hidden Files — Displays all applications, files, and vendors that are hidden by the administrator. Select this filter, then review the Applications, Executable Files, or Vendors panes for hidden applications, executable files, and vendors, respectively.
|
Filter actions | Duplicate — Opens the Duplicate dialog box that allows you to duplicate the selected filter. This option is available for all seeded and user-defined filters. Edit — Opens the Select View For Saved Search page that allows edit the filter configuration. This option is available only for user-defined filters. Rename — Opens the Rename dialog box that allows you to rename the selected filter. This option is available only for user-defined filters. Delete — Deletes the selected filter. This option is available only for user-defined filters.
|
Applications | View inventory details in the Application view. In the tree, applications and executable files are sorted into Trusted Applications, Malicious Applications, and Unknown Applications categories. |
Vendors | Displays inventory details in the Vendor view. For each vendor, you can view the Trusted, Malicious, and Unknown categories. |
Executable Files | View file information in the Application Name, Application Version, and Final Reputation views. In the Application and Vendor views, this pane lists the files associated with the node selected in the Applications or Vendors pane. In the Reputation Source column, if the reputation source is TIE, clicking TIE opens the TIE Reputations page or TIE Certificates Reputations Details page, as applicable. This allows you to view details for the selected file or the certificate for the file, as applicable. Hide Filter/Show Filter — Hides or shows the filters in the pane. Quick find — Specify the string to search for. You can search based on the file name. Apply — Filters the files list based on the specified string. Clear — Removes an applied filter. Show selected rows — Hides all rows except the rows selected in the Executable Files pane.
|
Actions | Export Table — Opens the Export page. Use this page to specify the format and the package of files to be exported. You can save or email inventory details. Choose Columns — Opens the Select the Columns to Display page where you can select columns of data to display in the Executable Files pane. Allow Files — Opens the Allow or Ban Files wizard where you can allow a file by adding it to the allow list or defining a rule. Ban Files — Opens the Allow or Ban Files wizard where you can ban a file by defining a rule. Export Inventory for Offline GTI Tool — Exports the SHA-1s of all executable files and public key SHA-1s of all certificates in the inventory to a file. Use this file to fetch Trellix GTI ratings by using the Offline GTI Tool. This action fetches Trellix GTI ratings for isolated ePO - On-prem environments (that do not have access to the Internet). Import GTI ratings — Imports Trellix GTI ratings from the GTI result file to the ePO - On-prem server. The GTI result file is created by the Offline GTI Tool after it fetches Trellix GTI ratings for SHA-1s. Use this action to fetch Trellix GTI ratings for isolated ePO - On-prem environments (that do not have access to the Internet). Set Reputation by Application Control — Opens the Set Reputation by Application Control dialog box where you can edit the reputation for the selected file. Hide Files/Show Files — Hides or shows the selected files in the pane. The hidden files are not listed in all seeded filters except the All Malicious Files, Allowed Malicious Files, and Hidden Files filters.
|