Cloud Workload Security 5.3.x Interface Reference Guide

Prev Next

Last Updated: September 17, 2023

Trellix CWS interface

You can manage all your virtual machine instances using Trellix Cloud Workload Security (Trellix CWS). The Trellix CWS console has a single user interface with several card-based panes for improved usability.

Trellix CWS summary card

After configuring and registering the cloud accounts with Trellix® ePolicy Orchestrator - On-prem, you can view the total number of workloads in the Trellix CWS summary card.

Option

Definition

Total Workloads

Total number of Virtual Machines (VMs) running in the registered cloud accounts.

  • Compliance Events — Number of high and medium risk instances according to the configured policies pertaining to security groups

  • Threat Events — Number of high and medium threats discovered by security products

Total Pods

Total number of pods in the registered Kubernetes cluster.

  • Compliance Events — Number of high risk instances according to the configured container assessment policies

Total Workloads — Compliance Events

You can view the list of compliance events, manage the workloads, and take remediation measures.

Compliance Events filter

View the compliance details of all powered-on instances under the Compliance Events pane.

Option

Definition

Issue

Displays the number of risk instances.

  • Instances with Trellix CWS assessment policies

  • Instances with security risks according to the policies pertaining to security groups

  • Instances where security controls and encryption are not installed

Product

Name of the product that discovers risk instances.

  • Security Group

  • Volume Encryption

  • Threat Prevention

  • Adaptive Threat Protection

  • Policy Auditor

  • Application Control

  • Change Control (FIM)

  • Network Intrusion Prevention

Tag

Displays the tags associated with the instances.

Workload

Displays the name of the workload.

View

Click to filter All, Workloads, Managed, and Unmanaged instances. Select a filter and search your instances in the search bar.

Take Action

Click to install the following security controls.
For managed workloads:

  • Install Trellix Agent

  • Install Threat Prevention

  • Install Application Control

  • Install Change Control (FIM)

  • Install Network IPS

  • Install Adaptive Threat Protection

  • Policy Auditor

  • Show Security Groups

  • Quarantine Workload

  • Shut Down Workload

  • Tag Workloads

  • Update DAT

For unmanaged workloads:

  • Install Trellix Agent

  • Show Security Groups

  • Quarantine Workload

  • Shut Down Workload

  • Tag Workload

Trellix ePO - On-prem Management

Manage your instances by installing Trellix Agent.

Option

Definition

Status

Displays if your instance has Trellix Agent installed on it.

Managed — Your instance has Trellix Agent installed.

UnmanagedTrellix Agent is not installed on your instance.

Version

Displays the installed Trellix Agent version.

DevOps Deployment Script

Use this script to deploy Trellix Agent.

Take Action

Select Install Trellix Agent to install Trellix Agent on your instance.

Show Security Groups

View all security groups associated with your instances.

Option

Definition

Workload

Displays the workload details.

Security Group

The name of the Security or Network Security group.

Association

Displays how many instances this security or the network security group is associated with.

Actions

Click

  • Edit Rules — to edit the rules in this security group.

  • Detach — to detach this security group from this instance. You can detach a security group only from your AWS instances.

Security Group — Rules

View the rules in each security group.

Property

Definition

Security Group

Name of the security group rule. For Azure instances, every security group rule has a name. This is not applicable for AWS instances.

Associated Workloads

Displays other instances that are associated with this security group (firewall).

Type

Displays the protocol type. You can change the protocol type.

Protocol

Displays the protocol allowed.

Direction

Displays whether the traffic is inbound or outbound.

Port Range

Displays the port range allowed.

Priority

Displays the priority of this rule in the security group.

Note: Priority is applicable only for Microsoft Azure Network Security Groups.

Access

Displays if this is an allow rule or deny rule for Microsoft Azure instances. You cannot edit the deny rules.

Source

The source IP address. You can choose Anywhere to allow connections from all traffic or Custom IP to provide an IP address that you want to allow. For AWS instances, you can also provide the security group for which you want to allow traffic.

Add Rule

Click to add new rule to this security group.

Apply Changes

Click to save your changes.

Threat Prevention

Protect your instance by installing the appropriate Trellix anti-malware software based on your operating system and cloud environment.

Option

Definition

On-Access General

Displays whether the On-Access General feature is installed.

On-Access ScriptScan

Displays whether the On-Access ScriptScan feature is installed.

Access Protection

Displays whether the Access Protection feature is installed.

Exploit Prevention

Displays whether the Exploit Prevention feature is installed.

DAT

Displays whether the DAT feature is installed.

Take Action

Select Install Trellix Threat Prevention to install Threat Prevention on your instances.

Adaptive Threat Protection

Install Adaptive Threat Protection to analyze the content from your enterprise, and decide what to do based on the file reputation, rules, and reputation thresholds.

Option definitions

Option

Definition

Adaptive Threat Protection

Displays whether Adaptive Threat Protection is installed.

Take Action

Select Install Trellix Adaptive Threat Protection to install Adaptive Threat Protection on your instances.

Policy Audit

Install Trellix® Policy Auditor to automate security audit processes, and report the audit results for internal and external policies consistently and accurately.

Option

Definition

Policy Audit Status

Displays whether Policy Auditor is installed.

Take Action

Select Install Policy Auditor to install Policy Auditor on your instances.

Application Control

Install Trellix® Application Control to protect your system from unauthorized applications.

Option

Definition

Application Control

Displays whether Application Control is installed.

Take Action

Select Install Trellix Application Control to install Application Control on your instances.

File Integrity Monitor

Install Trellix® Change Control file integrity monitoring solution to prevent any changes made in your environment that might lead to a security breach.

Option

Definition

Change Control

Displays whether Change Control is installed.

Take Action

Select Install Trellix Change Control to install Change Control on your instances.

Volume Encryption

See if your Amazon Web Services (AWS) volumes are encrypted or not. You can view the number of root and data volumes for your instances.

Option definitions

Option

Definition

Status

Displays the encryption status of the volumes.

Type

Displays the type of the volume (root or data volume).

ID

Displays the volume ID.

Network Intrusion Prevention

Protect your instances from sophisticated threats by installing Network Intrusion Prevention.

Option definitions

Option

Definition

Probe Status

Displays whether the vNSP probe is installed.

Protected Groups

Displays the list of protected groups.

Cluster

Displays the network cluster.

NSP Probe Deployment Script Download

Use the deployment script to deploy NSP probe.

Take Action

Select Install Network Intrusion Prevention to install Network Intrusion Prevention on your instances.

Threats

View the number of high risk and low risks instances.

Option

Definition

High Risk

Number of high risk events.

Low Risk

Number of low risk events.

System Properties

View the system properties of your instances.

Option

Definition

Location

The region of the instance as shown on the cloud vendor console.

Instance ID

The instance ID as shown on the cloud vendor console.

Instance Name

The instance name as shown on the cloud vendor console.

Instance Type

The hardware configuration selected for an instance.

Platform

Displays whether the platform is Microsoft Windows or Linux.

Power Status

Displays if this instance is running or if it is stopped.

Private DNS Name

The private DNS name from the cloud vendor console.

Private IP Address

The private IP address from AWS.

Public DNS Name

The public DNS name from the cloud vendor console.

Public IP Address

The public IP address from AWS accessed by Trellix ePO - On-prem.

Virtual Network ID

The ID of the virtual network of this instance.

Trellix ePO - On-prem Tags

Tag your instances with Trellix ePO - On-prem tags related to product deployment tasks. You can create auto tags for your instances based on account name and platform.

Option

Definition

Trellix ePO Tags

Trellix ePO - On-prem tags for this instance.

Tag Workloads

Click to add a tag to this instance.

Imported Cloud Tags

Import the user-defined AWS and Microsoft Azure tags assigned to the cloud instances with Trellix ePO - On-prem during cloud account registration.

Option

Definition

Cloud Tags

User-defined AWS or Microsoft Azure tags for this instance.

Add

Click to import the tag assigned to this instance in public cloud.

Assessment Policy

Create a custom policy to suit your environment.

Option

Definition

Take Action

Click to select an assessment policy for this instance.

Policy Catalog

Click to go to the Policy Catalog page to select or create a policy for this instance.

Total Workloads — Threat Events

You can view the list of threat events, the threat source, and the traffic details of your workloads.

Threat Events filters

View the threat details of all powered-on instances under the Threat Events pane.

Option

Definition

Issue

Displays the number of issues discovered by various security products.

  • Malicious Connection

  • Risk Port Assessment

  • Suspicious Connection

  • Blocked Connection

  • Malware Detected

  • Exploit Prevention

  • Malicious Behavior Detected

  • Advanced Malware Detected

  • Network Prevention Alerts

  • GuardDuty

  • Application Control Events

  • Change Control Events

Threat Source

Name of the threat source that discovers risk instances.

  • Traffic Anomalies Detection

  • Threat Protection

  • Adaptive Threat Protection

  • Network Intrusion Prevention

  • Amazon Web Services

  • Application Control

  • Change Control

Tag

Displays the tags associated with the instances.

Workload

Displays the name of the workload.

View

Click to filter All, Workloads, Managed, and Unmanaged instances. Select a filter and search your instances in the search bar.

Graph

Click to view traffic details and network flow logs for the selected workload.

Traffic pane

View various blocked internal connections, and the accepted suspicious and malicious external connections to and from your AWS and Azure instances. The internal and external traffic is captured as East-West and North-South traffic respectively. The traffic displayed is the data accumulated for a maximum of seven days.

Option

Definition

Time

Displays the system date and time.

Time Range (+/-)

Click to filter instances based on occurrence over a particular period.

  • 1 minute

  • 5 minutes

  • 15 minutes

  • 30 minutes

Show

Click Inbound, Outbound, and Blocked connections or a combination of these filters to filter instances based on traffic flow.

Table

Click to go back to Threat Events pane.

Show Security Groups

Click to open the security groups associated with this instance.

Shut Down Workload

Click to shut down the workload.

Quarantine Workload

Click to quarantine the workload.

Event Details pane

View all information related to your threat instances in the Event Details pane.

Option

Definition

Event ID

Identification number of this instance.

Detected By

Name of the product that discovered this event.

Severity

Displays whether this event is a high risk event or low risk event.

Direction

Displays if the traffic is Inbound (N-S), Outbound (N-S), Inbound (E-W), Outbound (E-W), bidirectional (E-W), bidirectional (N-S).

Note: N-S indicates external traffic and E-W indicates internal traffic.

Source

The source IP address of the traffic to this instance.

Country of Origin

Name of the country from where the traffic for this instance originated.

GTI Reputation

The Trellix® Global Threat Intelligence reputation status for this instance.

Source Port

The source port number.

Destination

The destination IP address for the traffic to this instance.

Destination Port

The destination port number.

Protocol

The protocol name.

Action Taken

Displays whether the traffic to this instance is accepted or blocked.

Occurrence

The number of occurrences of this event.

Workload

The name of the workload.

Compliance

The number of compliance alarms associated with this instance.

Edit Inbound Rules for

Click to open the security groups associated with this instance.

Group

The name of the group associated with this instance.

Take Action

Select:

  • Quarantine Workload to quarantine the malicious workload from spreading malware to other workloads.

  • Run On-demand Scan to manually scan your workloads.

  • Shut Down Workload to shut down the workload.

Total Pods — Compliance Events

You can view the list of the pods and take remediation measures for your instances.

Compliance Events filters

View the details of all powered-on pods under the Compliance Events pane.

You can view the details of the Trellix anti-malware software such as Trellix® Endpoint Security (ENS) installed and configured on your instances.

Option

Definition

Issue

Displays the number of issues.

Product

The name of the product that discovers the issue.

  • Container Firewall

Labels

The name of the label.

Option

Definition

Pod

The name of the pod.

Search by Label

Click to search the pods based on label.

Take Action

Click:

  • Assign Network policy — to set network policies for the selected pod.

  • Quarantine Pod — to quarantine the selected pod.

Pod Status

Displays whether the pod is turned on or not.

Namespace

Displays the namespace details of the pod.

Pod Network Policy

View the network policies assigned to your pods. Network policy resources use labels to define rules to allow or deny traffic to the selected pod.

Option definitions

Option

Definition

Namespace

Displays the namespace details of the pod.

Select Pod Label

Select the label of the selected pod.

Action

Allow or deny the incoming and outgoing traffic to the pod.

  • Allow

  • Deny All

Direction

Direction of the traffic.

  • Incoming

  • Outgoing

Option

Definition

Peers

Displays the traffic source.

  • Any — Allow traffic from any source.

  • IP Address — Allow traffic from a specific IP address.

  • Namespace Selector — Allow traffic from a specific namespace.

  • Pod Selector — Allow traffic from a specific pod.

Port

Displays the port name.

Protocol

Displays the protocol name.

Add Rule

Click to add new rule.

Apply Changes

Click to save your changes.

Registered cloud account details

After configuring and registering your cloud accounts with Trellix ePO - On-prem, view your account details in System Tree on the Trellix ePO - On-prem server.

Virtual machine details for AWS cloud account

After importing the discovered VMs from the cloud accounts, the VM details are displayed in the System Tree.

Property

Description

System Name

The name of the VM.

Managed State

Specifies if the system is managed by Trellix Agent.

Tags

The tag applied to this VM.

IP Address

The IP address of the VM.

User Name

The user name of the user logged on to the system.

Last Communication

The time of the last synchronization.

You can view more details of your AWS account by selecting and adding the required column using the Choose Columns option under System Tree → Actions. By default, these columns don't appear under System Tree.

You can view the virtualization properties of the selected virtual machine by navigating to Menu → Systems → System Tree and double-clicking the target virtual machine.

Property

Description

Vendor Name

The name of the cloud vendor.

Account Name

The name of the cloud account.

Unique ID

The unique ID of the instance.

Property

Description

Power Status

Displays if the instance is turned on or off.

Instance ID

The unique value provided to the instance from AWS.

Instance Name

The instance name as shown on the AWS console.

Image ID

The unique value of Amazon machine image with which the instance was created.

Private DNS name

The private DNS name from AWS.

Public DNS name

The public DNS name from AWS.

State Transition Reason

The reason for the instance to move from one state to another from the AWS console.

Key Name

The key name of the instance that is provided during the launch.

Instance Type

The hardware configuration selected for an instance during the launch.

Launch Time

The time the instance is launched in AWS.

Availability Zone

The region where the instance is created in AWS.

Platform

Specifies whether the platform is Microsoft Windows or Linux.

Private IP Address

The private IP address from AWS.

Public IP Address

The public IP address from AWS, are accessed by Trellix ePO - On-prem.

VPC ID

The Amazon Virtual Private cloud ID.

MAC Address

The MAC address of an instance in Amazon Virtual private cloud.

Architecture

Provides details about the hardware specifications of the processor. For example, x86_64, i386.

Virtualization Type

The virtualization type of VM like HVM and paravirtualization.

Tags

The tags of the VMs.

Security Groups

The security group details where the instance is linked in AWS.

Network Interfaces

Display details about all network interfaces associated with the EC2 instance.

Virtual machine details for Microsoft Azure account

After importing the discovered VMs from the cloud accounts, the VM details are displayed in System Tree.

You will have VMs from your Microsoft Azure accounts displayed here.

Property

Description

System Name

The name of the VM.

Managed State

Specifies if the system is managed by Trellix Agent.

Tags

The tag applied on this VM.

IP Address

The IP address of the VM.

User Name

The user name of the user logged on to the system.

Last Communication

The time of the last synchronization.

You can view more details of the cloud accounts by selecting and adding the required columns using the Choose Columns option under System Tree → Actions. By default, these columns don't appear under System Tree.

From Choose Columns, select Vendor, and you can see the name of the vendor for your cloud account.

You can view the virtualization properties of the selected VM by navigating to Menu → Systems → System Tree. Double-click the target VM and click the Virtualization tab.

Property

Description

Vendor Name

The name of the cloud account vendor.

Account Name

The name of the account in Trellix ePO - On-prem.

Power Status

Displays if the system is in running or stopped state.

Created Time

The time when the instance is created.

Image ID

The unique image value provided to the instance from the cloud account.

Instance ID, Unique ID

The unique value provided to the instance from the cloud account.

Instance Size

The hardware configuration selected for an instance during the launch.

IP Address

The IP address from the cloud account.

Last Modified Time

The time when the instance was last modified in the cloud account.

Location

The location of the instance.

Platform

Specifies whether the platform is Microsoft Windows or Linux.

Public DNS

The public DNS name from the cloud account.

Virtual IP Address

The virtual IP address of the instance.

Network Security Group

The network security group associated with this instance.

Instance Endpoints

The instance endpoints.

Note

For VMs with managed disks, Image ID is replaced by the VM's Unique ID.

Virtual machine details for OpenStack account

After importing the discovered VMs from the cloud accounts, the VM details are displayed in System Tree.

You will have VMs from your OpenStack accounts displayed here.

Property

Description

System Name

The name of the VM.

Managed State

Specifies if the system is managed by Trellix Agent.

Tags

The tag applied on this VM.

IP Address

The IP address of the VM.

User Name

The user name of the user logged on to the system.

Last Communication

The time of the last synchronization.

You can view more details of the cloud accounts by selecting and adding the required columns using the Choose Columns option under System Tree → Actions. By default, these columns don't appear under System Tree.

From Choose Columns, select Vendor, and you can see the name of the vendor for your cloud account.

You can view the virtualization properties of the selected VM by navigating to Menu → Systems → System Tree. Double-click the

target VM and click the Virtualization tab.

Property

Description

Vendor Name

The name of the cloud account vendor.

Account Name

The name of the account in Trellix ePO - On-prem.

Unique ID

The unique ID of the instance.

Power Status

Displays if the system is in running or stopped state.

Instance ID

The instance name as shown on the OpenStack console.

Image ID

The unique image value provided to the instance from the cloud account.

Key Name

The key name of the instance that is provided during the launch.

Instance Type

The hardware configuration selected for an instance during the launch.

Launch Time

The time the instance is launched in OpenStack.

Availability Zone

The region where the instance is created in OpenStack.

Platform

Specifies whether the platform is Microsoft Windows or Linux.

Private IP Address

The private IP address from OpenStack.

Public IP Address

The public IP address from OpenStack that are accessed by Trellix ePO - On-prem.

Tags

The tags associate with OpenStack VMs.

Hypervisor Host Name

The host name of the hypervisor.

Hypervisor Version

Displays the hypervisor version.

Hypervisor Type

Displays the hypervisor type.

Note

For VMs with managed disks, Image ID is replaced by the VM's Unique ID.

Virtual machine details for VMware vSphere account

View the account summary for your registered VMware vSphere account in the Registered Cloud Accounts page.

Option

Definition

Actions

  • Add Cloud Account — Opens a page that allows you to add a cloud account.

  • Choose Columns — Opens a dialog box that allows you to select which columns to display.

  • Export Table — Opens the Export page. Use this to specify the format and the package of files to be exported. You can save, email, or export the file.

Name

Name of the cloud account that you registered in Trellix ePO - On‑prem.

Type

Name of the cloud account vendor.

Last Successful Sync

The date and time when the last successful synchronization between Trellix ePO - On‑prem and the cloud account occurred.

Last Sync Status

Displays the synchronization status, including Sync Scheduled, Success, In Progress, and Failed. Hover your mouse over this property to know the start and end times of your account synchronization. If your account synchronization is in progress, you can see the sync start time.

Total VMs

The number of VMs that are available under the registered cloud account.

Running VMs

The number of VMs that are up and running under the registered cloud account.

Managed VMs

The number of VMs that are managed by Trellix ePO - On-prem.

Auto Deploy MA

Specifies if the administrator has enabled the Auto deploy Trellix Agent task for the registered cloud account.

Tags

Displays the tags of the VMs.

Actions

You can edit, delete, and synchronize the cloud account using Trellix ePO - On-prem.