Search for certificates in the TIE database.
The longer the module runs in your environment, the more populated the database. A certificate is added to the database when the module requests information about it.
Option definitions
Option | Definition |
|---|
Custom | Search for certificates using a custom filter. You can use one of the default filters, or create your own: Malicious Certificates — Lists certificates with a malicious reputation. This includes certificates whose reputation is Known Malicious, Might be Malicious, and Most Likely Malicious. Unknown in GTI — Lists certificates whose reputation is unknown in Trellix Global Threat Intelligence. Add... — Create a custom search filter. Click Add... to specify the search criteria. The custom filter is named "Unsaved". Click the right arrow next to the Unsaved label, then click Edit to name the filter.
|
Quick find | Search for a specific certificate. You can use the search characters * or ?. |
Show selected rows | Lists only certificates that are selected. |
Selecting a column heading | Select a column heading to sort the information. When sorting by any type of reputation, for example by Enterprise or Trellix Global Threat Intelligence reputation, the certificates are listed in this order: Known Trusted Most Likely Trusted Unknown Most Likely Malicious Known Malicious Not Set
Sorting results appear by reputation value rather than alphabetically. For more information about the values, see Specifying the reputation as a number.
When TIE doesn't have information available for a file or its reputation, in the Reputation column appears "Not Available".
|
Selecting a certificate | Select a certificate to see details about it. |
Actions | See Certificate actions. |