Analyze the suggestions available for an observation and take actions.
Option definitions
Option
Definition
Binary Tree
Represents the hierarchy and relationship between the file and its parent process. Also, allows you to review information for all child observations associated with the opened collated observation. By default, the file associated with the collated observation is selected in this pane.
Suggestions tab
Binary Info pane
Displays detailed information for the selected binary file and lists all actions you can perform for the file. Depending on the file's properties and attributes, one or more of the following actions are available for the file.
Add as Installer — Adds the program (or installer) as an authorized installer for your setup.
Add as Updater — Adds the program as an authorized updater for your setup.
Add to Allow list — Adds the file to the allow list for a specific endpoint. This action does not result in any rule group or policy changes.
Add Parent as Updater — Adds the parent program as an updater for your setup.
Add as Exception — Defines a rule to allow the file to override or bypass the applied memory-protection techniques.
Add by binary SHA-1 — Authorizes the binary file to run on endpoints based on its checksum value.
Add as Trusted Directory — Adds the location for the file as a trusted directory for your environment. The added trusted directory is provided updater privileges.
Certificate Info pane
Displays information for the certificate, if any, associated with the file. This pane is displayed only if a certificate is associated with the selected file.
Add Certificate — Adds the certificate as a trusted certificate.
Rule Group pane
Displays the various rules to be added to the rule group. By default, this pane is empty and is populated based on the actions you perform.
Files to be Allow listed pane
Displays the various files to be allow listed on the endpoint. By default, this pane is empty and is populated only when you choose the Add to Allow list action.
Add — Opens the Add to allow list dialog box. Specify the binary path name.
Remove — Deletes the selected rule.
Edit — Opens the Add to allow list dialog box with information for a selected rule. Edit the details as needed, then click OK.
Observations tab
Displays detailed information for observations in a tabular format.
Dismiss
Ignores the observation.
Approve
Saves the changes made and approve the observation.
Cancel
Exits without saving changes and return to the Observations (Deprecated) page.
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Interface Reference
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Interface Reference
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Interface Reference