Review details for an executable file.
You can access this page when you click a file name (in the Executable Files pane) from any of these pages:
Option definitions
Option | Definition |
|---|
File Details | Lists relevant details for the selected file. File Name — Displays the name of the selected file. Also, clicking Lookup in TIE opens the TIE Reputations page that allows you to view or edit the file reputation. File Version — Displays the version information for the selected file. Path — Displays the path of the selected file. First Seen System — Displays the system where the selected file was detected for the first time in enterprise. First Seen Time — Displays the date and time when the selected file was detected for the first time in enterprise. Final Reputation — Displays the final reputation for the selected file. The color in which the reputation is displayed indicates whether the file is trusted, malicious, or unknown.
|
Color | Reputation |
Green | Known Trusted |
Most Likely Trusted |
Might be Trusted |
Orange | Unknown |
Red | Might be Malicious |
Most Likely Malicious |
Known Malicious |
File SHA-1 — Displays the SHA-1 value for the selected file. File SHA-256 — Displays the SHA-256 value for the selected file. File MD5 — Displays the MD5 value for the selected file. Application — Displays the application to which the selected file is linked. Certificate — Displays the name of the certificate vendor. The color in which the vendor is displayed indicates whether the file is trusted (Green), malicious (Red), or unknown (Orange). Click the vendor name to review the following additional details. Also, clicking Lookup in TIE opens the TIE Certificate Reputations Details page, which allows you to view or edit the certificate reputation. Subject — Name of the certificate vendor. Issuer — Name of the certificate signing authority. Certificate Reputation — Reputation of the certificate. Possible values are Known Trusted, Most Likely Trusted, Might be Trusted, Unknown, Might be Malicious, Most Likely Malicious, and Known Malicious. The color in which the Certificate Reputation is displayed indicates whether the certificate is trusted (Green), malicious (Red), or unknown (Orange). Reputation Source — Indicates the reputation source. Possible values are TIE and GTI. Public Key Algorithm — Indicates the algorithm used to create the public key to encrypt messages. Public Key Length — Specifies the length of the public key in bits. Public Key Hash — Displays the public key hash. Certificate Hash — Displays the certificate hash. Valid From — Indicates the date from which the certificate is valid. Valid To — Indicates the date till which the certificate is valid.
|
Execution Status in Enterprise Inventory | Displays the execution status of the selected file in your enterprise. You can view the number on systems where the file is allowed or banned. |
File observed on systems | Lists all endpoints with the selected file. Hide Filter/Show Filter — Hides or shows the filter options in the pane. Preset — Filters the systems list based on whether the file is allowed or banned on the endpoints. Quick find — Specifies the string to search for. You can search based on the system name. Apply — Filters the list based on the specified string. Clear — Removes an applied filter. Execution Permission — Lists the reason or cause associated with the execution status of a file. Possible values are:
|
Actions | Allow/Ban — Opens the Allow or Ban Files wizard where you can allow or ban the file by defining a rule. View Events — Opens the Solidcore Events page where you can view events generated for selected system and file. Export Table — Opens the Export page where you can specify the format and the package of files to be exported. You can save or email file details. Choose Columns — Opens the Select the Columns to Display page where you can select the columns of data to display in the File observed on systems pane.
|