Last Updated: September 17, 2023
Trellix CWS interface
You can manage all your virtual machine instances using Trellix Cloud Workload Security (Trellix CWS). The Trellix CWS console has a single user interface with several card-based panes for improved usability.
Trellix CWS summary card
After configuring and registering the cloud accounts with Trellix® ePolicy Orchestrator - On-prem, you can view the total number of workloads in the Trellix CWS summary card.
Option | Definition |
|---|---|
Total Workloads | Total number of Virtual Machines (VMs) running in the registered cloud accounts.
|
Total Pods | Total number of pods in the registered Kubernetes cluster.
|
Total Workloads — Compliance Events
You can view the list of compliance events, manage the workloads, and take remediation measures.
Compliance Events filter
View the compliance details of all powered-on instances under the Compliance Events pane.
Option | Definition |
|---|---|
Issue | Displays the number of risk instances.
|
Product | Name of the product that discovers risk instances.
|
Tag | Displays the tags associated with the instances. |
Workload | Displays the name of the workload. |
View | Click to filter All, Workloads, Managed, and Unmanaged instances. Select a filter and search your instances in the search bar. |
Take Action | Click to install the following security controls.
For unmanaged workloads:
|
Trellix ePO - On-prem Management
Manage your instances by installing Trellix Agent.
Option | Definition |
|---|---|
Status | Displays if your instance has Trellix Agent installed on it. Managed — Your instance has Trellix Agent installed. Unmanaged — Trellix Agent is not installed on your instance. |
Version | Displays the installed Trellix Agent version. |
DevOps Deployment Script | Use this script to deploy Trellix Agent. |
Take Action | Select Install Trellix Agent to install Trellix Agent on your instance. |
Show Security Groups
View all security groups associated with your instances.
Option | Definition |
|---|---|
Workload | Displays the workload details. |
Security Group | The name of the Security or Network Security group. |
Association | Displays how many instances this security or the network security group is associated with. |
Actions | Click
|
Security Group — Rules
View the rules in each security group.
Property | Definition |
|---|---|
Security Group | Name of the security group rule. For Azure instances, every security group rule has a name. This is not applicable for AWS instances. |
Associated Workloads | Displays other instances that are associated with this security group (firewall). |
Type | Displays the protocol type. You can change the protocol type. |
Protocol | Displays the protocol allowed. |
Direction | Displays whether the traffic is inbound or outbound. |
Port Range | Displays the port range allowed. |
Priority | Displays the priority of this rule in the security group.
|
Access | Displays if this is an allow rule or deny rule for Microsoft Azure instances. You cannot edit the deny rules. |
Source | The source IP address. You can choose Anywhere to allow connections from all traffic or Custom IP to provide an IP address that you want to allow. For AWS instances, you can also provide the security group for which you want to allow traffic. |
Add Rule | Click to add new rule to this security group. |
Apply Changes | Click to save your changes. |
Threat Prevention
Protect your instance by installing the appropriate Trellix anti-malware software based on your operating system and cloud environment.
Option | Definition |
|---|---|
On-Access General | Displays whether the On-Access General feature is installed. |
On-Access ScriptScan | Displays whether the On-Access ScriptScan feature is installed. |
Access Protection | Displays whether the Access Protection feature is installed. |
Exploit Prevention | Displays whether the Exploit Prevention feature is installed. |
DAT | Displays whether the DAT feature is installed. |
Take Action | Select Install Trellix Threat Prevention to install Threat Prevention on your instances. |
Adaptive Threat Protection
Install Adaptive Threat Protection to analyze the content from your enterprise, and decide what to do based on the file reputation, rules, and reputation thresholds.
Option definitions
Option | Definition |
|---|---|
Adaptive Threat Protection | Displays whether Adaptive Threat Protection is installed. |
Take Action | Select Install Trellix Adaptive Threat Protection to install Adaptive Threat Protection on your instances. |
Policy Audit
Install Trellix® Policy Auditor to automate security audit processes, and report the audit results for internal and external policies consistently and accurately.
Option | Definition |
|---|---|
Policy Audit Status | Displays whether Policy Auditor is installed. |
Take Action | Select Install Policy Auditor to install Policy Auditor on your instances. |
Application Control
Install Trellix® Application Control to protect your system from unauthorized applications.
Option | Definition |
|---|---|
Application Control | Displays whether Application Control is installed. |
Take Action | Select Install Trellix Application Control to install Application Control on your instances. |
File Integrity Monitor
Install Trellix® Change Control file integrity monitoring solution to prevent any changes made in your environment that might lead to a security breach.
Option | Definition |
|---|---|
Change Control | Displays whether Change Control is installed. |
Take Action | Select Install Trellix Change Control to install Change Control on your instances. |
Volume Encryption
See if your Amazon Web Services (AWS) volumes are encrypted or not. You can view the number of root and data volumes for your instances.
Option definitions
Option | Definition |
|---|---|
Status | Displays the encryption status of the volumes. |
Type | Displays the type of the volume (root or data volume). |
ID | Displays the volume ID. |
Network Intrusion Prevention
Protect your instances from sophisticated threats by installing Network Intrusion Prevention.
Option definitions
Option | Definition |
|---|---|
Probe Status | Displays whether the vNSP probe is installed. |
Protected Groups | Displays the list of protected groups. |
Cluster | Displays the network cluster. |
NSP Probe Deployment Script Download | Use the deployment script to deploy NSP probe. |
Take Action | Select Install Network Intrusion Prevention to install Network Intrusion Prevention on your instances. |
Threats
View the number of high risk and low risks instances.
Option | Definition |
|---|---|
High Risk | Number of high risk events. |
Low Risk | Number of low risk events. |
System Properties
View the system properties of your instances.
Option | Definition |
|---|---|
Location | The region of the instance as shown on the cloud vendor console. |
Instance ID | The instance ID as shown on the cloud vendor console. |
Instance Name | The instance name as shown on the cloud vendor console. |
Instance Type | The hardware configuration selected for an instance. |
Platform | Displays whether the platform is Microsoft Windows or Linux. |
Power Status | Displays if this instance is running or if it is stopped. |
Private DNS Name | The private DNS name from the cloud vendor console. |
Private IP Address | The private IP address from AWS. |
Public DNS Name | The public DNS name from the cloud vendor console. |
Public IP Address | The public IP address from AWS accessed by Trellix ePO - On-prem. |
Virtual Network ID | The ID of the virtual network of this instance. |
Trellix ePO - On-prem Tags
Tag your instances with Trellix ePO - On-prem tags related to product deployment tasks. You can create auto tags for your instances based on account name and platform.
Option | Definition |
|---|---|
Trellix ePO Tags | Trellix ePO - On-prem tags for this instance. |
Tag Workloads | Click to add a tag to this instance. |
Imported Cloud Tags
Import the user-defined AWS and Microsoft Azure tags assigned to the cloud instances with Trellix ePO - On-prem during cloud account registration.
Option | Definition |
|---|---|
Cloud Tags | User-defined AWS or Microsoft Azure tags for this instance. |
Add | Click to import the tag assigned to this instance in public cloud. |
Assessment Policy
Create a custom policy to suit your environment.
Option | Definition |
|---|---|
Take Action | Click to select an assessment policy for this instance. |
Policy Catalog | Click to go to the Policy Catalog page to select or create a policy for this instance. |
Total Workloads — Threat Events
You can view the list of threat events, the threat source, and the traffic details of your workloads.
Threat Events filters
View the threat details of all powered-on instances under the Threat Events pane.
Option | Definition |
|---|---|
Issue | Displays the number of issues discovered by various security products.
|
Threat Source | Name of the threat source that discovers risk instances.
|
Tag | Displays the tags associated with the instances. |
Workload | Displays the name of the workload. |
View | Click to filter All, Workloads, Managed, and Unmanaged instances. Select a filter and search your instances in the search bar. |
Graph | Click to view traffic details and network flow logs for the selected workload. |
View various blocked internal connections, and the accepted suspicious and malicious external connections to and from your AWS and Azure instances. The internal and external traffic is captured as East-West and North-South traffic respectively. The traffic displayed is the data accumulated for a maximum of seven days.
Option | Definition |
|---|---|
Time | Displays the system date and time. |
Time Range (+/-) | Click to filter instances based on occurrence over a particular period.
|
Show | Click Inbound, Outbound, and Blocked connections or a combination of these filters to filter instances based on traffic flow. |
Table | Click to go back to Threat Events pane. |
Show Security Groups | Click to open the security groups associated with this instance. |
Shut Down Workload | Click to shut down the workload. |
Quarantine Workload | Click to quarantine the workload. |
Event Details pane
View all information related to your threat instances in the Event Details pane.
Option | Definition |
|---|---|
Event ID | Identification number of this instance. |
Detected By | Name of the product that discovered this event. |
Severity | Displays whether this event is a high risk event or low risk event. |
Direction | Displays if the traffic is Inbound (N-S), Outbound (N-S), Inbound (E-W), Outbound (E-W), bidirectional (E-W), bidirectional (N-S).
|
Source | The source IP address of the traffic to this instance. |
Country of Origin | Name of the country from where the traffic for this instance originated. |
GTI Reputation | The Trellix® Global Threat Intelligence reputation status for this instance. |
Source Port | The source port number. |
Destination | The destination IP address for the traffic to this instance. |
Destination Port | The destination port number. |
Protocol | The protocol name. |
Action Taken | Displays whether the traffic to this instance is accepted or blocked. |
Occurrence | The number of occurrences of this event. |
Workload | The name of the workload. |
Compliance | The number of compliance alarms associated with this instance. |
Edit Inbound Rules for | Click to open the security groups associated with this instance. |
Group | The name of the group associated with this instance. |
Take Action | Select:
|
Total Pods — Compliance Events
You can view the list of the pods and take remediation measures for your instances.
Compliance Events filters
View the details of all powered-on pods under the Compliance Events pane.
You can view the details of the Trellix anti-malware software such as Trellix® Endpoint Security (ENS) installed and configured on your instances.
Option | Definition |
|---|---|
Issue | Displays the number of issues. |
Product | The name of the product that discovers the issue.
|
Labels | The name of the label. |
Option | Definition |
|---|---|
Pod | The name of the pod. |
Search by Label | Click to search the pods based on label. |
Take Action | Click:
|
Pod Status | Displays whether the pod is turned on or not. |
Namespace | Displays the namespace details of the pod. |
View the network policies assigned to your pods. Network policy resources use labels to define rules to allow or deny traffic to the selected pod.
Option | Definition |
|---|---|
Namespace | Displays the namespace details of the pod. |
Select Pod Label | Select the label of the selected pod. |
Action | Allow or deny the incoming and outgoing traffic to the pod.
|
Direction | Direction of the traffic.
|
Option | Definition |
|---|---|
Peers | Displays the traffic source.
|
Port | Displays the port name. |
Protocol | Displays the protocol name. |
Add Rule | Click to add new rule. |
Apply Changes | Click to save your changes. |
Registered cloud account details
After configuring and registering your cloud accounts with Trellix ePO - On-prem, view your account details in System Tree on the Trellix ePO - On-prem server.
Virtual machine details for AWS cloud account
After importing the discovered VMs from the cloud accounts, the VM details are displayed in the System Tree.
Property | Description |
|---|---|
System Name | The name of the VM. |
Managed State | Specifies if the system is managed by Trellix Agent. |
Tags | The tag applied to this VM. |
IP Address | The IP address of the VM. |
User Name | The user name of the user logged on to the system. |
Last Communication | The time of the last synchronization. |
You can view more details of your AWS account by selecting and adding the required column using the Choose Columns option under System Tree → Actions. By default, these columns don't appear under System Tree.
You can view the virtualization properties of the selected virtual machine by navigating to Menu → Systems → System Tree and double-clicking the target virtual machine.
Property | Description |
|---|---|
Vendor Name | The name of the cloud vendor. |
Account Name | The name of the cloud account. |
Unique ID | The unique ID of the instance. |
Property | Description |
|---|---|
Power Status | Displays if the instance is turned on or off. |
Instance ID | The unique value provided to the instance from AWS. |
Instance Name | The instance name as shown on the AWS console. |
Image ID | The unique value of Amazon machine image with which the instance was created. |
Private DNS name | The private DNS name from AWS. |
Public DNS name | The public DNS name from AWS. |
State Transition Reason | The reason for the instance to move from one state to another from the AWS console. |
Key Name | The key name of the instance that is provided during the launch. |
Instance Type | The hardware configuration selected for an instance during the launch. |
Launch Time | The time the instance is launched in AWS. |
Availability Zone | The region where the instance is created in AWS. |
Platform | Specifies whether the platform is Microsoft Windows or Linux. |
Private IP Address | The private IP address from AWS. |
Public IP Address | The public IP address from AWS, are accessed by Trellix ePO - On-prem. |
VPC ID | The Amazon Virtual Private cloud ID. |
MAC Address | The MAC address of an instance in Amazon Virtual private cloud. |
Architecture | Provides details about the hardware specifications of the processor. For example, x86_64, i386. |
Virtualization Type | The virtualization type of VM like HVM and paravirtualization. |
Tags | The tags of the VMs. |
Security Groups | The security group details where the instance is linked in AWS. |
Network Interfaces | Display details about all network interfaces associated with the EC2 instance. |
Virtual machine details for Microsoft Azure account
After importing the discovered VMs from the cloud accounts, the VM details are displayed in System Tree.
You will have VMs from your Microsoft Azure accounts displayed here.
Property | Description |
|---|---|
System Name | The name of the VM. |
Managed State | Specifies if the system is managed by Trellix Agent. |
Tags | The tag applied on this VM. |
IP Address | The IP address of the VM. |
User Name | The user name of the user logged on to the system. |
Last Communication | The time of the last synchronization. |
You can view more details of the cloud accounts by selecting and adding the required columns using the Choose Columns option under System Tree → Actions. By default, these columns don't appear under System Tree.
From Choose Columns, select Vendor, and you can see the name of the vendor for your cloud account.
You can view the virtualization properties of the selected VM by navigating to Menu → Systems → System Tree. Double-click the target VM and click the Virtualization tab.
Property | Description |
|---|---|
Vendor Name | The name of the cloud account vendor. |
Account Name | The name of the account in Trellix ePO - On-prem. |
Power Status | Displays if the system is in running or stopped state. |
Created Time | The time when the instance is created. |
Image ID | The unique image value provided to the instance from the cloud account. |
Instance ID, Unique ID | The unique value provided to the instance from the cloud account. |
Instance Size | The hardware configuration selected for an instance during the launch. |
IP Address | The IP address from the cloud account. |
Last Modified Time | The time when the instance was last modified in the cloud account. |
Location | The location of the instance. |
Platform | Specifies whether the platform is Microsoft Windows or Linux. |
Public DNS | The public DNS name from the cloud account. |
Virtual IP Address | The virtual IP address of the instance. |
Network Security Group | The network security group associated with this instance. |
Instance Endpoints | The instance endpoints. |
Note
For VMs with managed disks, Image ID is replaced by the VM's Unique ID.
Virtual machine details for OpenStack account
After importing the discovered VMs from the cloud accounts, the VM details are displayed in System Tree.
You will have VMs from your OpenStack accounts displayed here.
Property | Description |
|---|---|
System Name | The name of the VM. |
Managed State | Specifies if the system is managed by Trellix Agent. |
Tags | The tag applied on this VM. |
IP Address | The IP address of the VM. |
User Name | The user name of the user logged on to the system. |
Last Communication | The time of the last synchronization. |
You can view more details of the cloud accounts by selecting and adding the required columns using the Choose Columns option under System Tree → Actions. By default, these columns don't appear under System Tree.
From Choose Columns, select Vendor, and you can see the name of the vendor for your cloud account.
You can view the virtualization properties of the selected VM by navigating to Menu → Systems → System Tree. Double-click the
target VM and click the Virtualization tab.
Property | Description |
|---|---|
Vendor Name | The name of the cloud account vendor. |
Account Name | The name of the account in Trellix ePO - On-prem. |
Unique ID | The unique ID of the instance. |
Power Status | Displays if the system is in running or stopped state. |
Instance ID | The instance name as shown on the OpenStack console. |
Image ID | The unique image value provided to the instance from the cloud account. |
Key Name | The key name of the instance that is provided during the launch. |
Instance Type | The hardware configuration selected for an instance during the launch. |
Launch Time | The time the instance is launched in OpenStack. |
Availability Zone | The region where the instance is created in OpenStack. |
Platform | Specifies whether the platform is Microsoft Windows or Linux. |
Private IP Address | The private IP address from OpenStack. |
Public IP Address | The public IP address from OpenStack that are accessed by Trellix ePO - On-prem. |
Tags | The tags associate with OpenStack VMs. |
Hypervisor Host Name | The host name of the hypervisor. |
Hypervisor Version | Displays the hypervisor version. |
Hypervisor Type | Displays the hypervisor type. |
Note
For VMs with managed disks, Image ID is replaced by the VM's Unique ID.
Virtual machine details for VMware vSphere account
View the account summary for your registered VMware vSphere account in the Registered Cloud Accounts page.
Option | Definition |
|---|---|
Actions |
|
Name | Name of the cloud account that you registered in Trellix ePO - On‑prem. |
Type | Name of the cloud account vendor. |
Last Successful Sync | The date and time when the last successful synchronization between Trellix ePO - On‑prem and the cloud account occurred. |
Last Sync Status | Displays the synchronization status, including Sync Scheduled, Success, In Progress, and Failed. Hover your mouse over this property to know the start and end times of your account synchronization. If your account synchronization is in progress, you can see the sync start time. |
Total VMs | The number of VMs that are available under the registered cloud account. |
Running VMs | The number of VMs that are up and running under the registered cloud account. |
Managed VMs | The number of VMs that are managed by Trellix ePO - On-prem. |
Auto Deploy MA | Specifies if the administrator has enabled the Auto deploy Trellix Agent task for the registered cloud account. |
Tags | Displays the tags of the VMs. |
Actions | You can edit, delete, and synchronize the cloud account using Trellix ePO - On-prem. |