Observations Detail (Deprecated) page

Prev Next

Analyze the suggestions available for an observation and take actions.

Option definitions

Option

Definition

Binary Tree

Represents the hierarchy and relationship between the file and its parent process. Also, allows you to review information for all child observations associated with the opened collated observation. By default, the file associated with the collated observation is selected in this pane.

Suggestions tab

Binary Info pane

Displays detailed information for the selected binary file and lists all actions you can perform for the file. Depending on the file's properties and attributes, one or more of the following actions are available for the file.

  • Add as Installer — Adds the program (or installer) as an authorized installer for your setup.

  • Add as Updater — Adds the program as an authorized updater for your setup.

  • Add to Allow list — Adds the file to the allow list for a specific endpoint. This action does not result in any rule group or policy changes.

  • Add Parent as Updater — Adds the parent program as an updater for your setup.

  • Add as Exception — Defines a rule to allow the file to override or bypass the applied memory-protection techniques.

  • Add by binary SHA-1 — Authorizes the binary file to run on endpoints based on its checksum value.

  • Add as Trusted Directory — Adds the location for the file as a trusted directory for your environment. The added trusted directory is provided updater privileges.

Certificate Info pane

Displays information for the certificate, if any, associated with the file. This pane is displayed only if a certificate is associated with the selected file.

  • Add Certificate — Adds the certificate as a trusted certificate.

Rule Group pane

Displays the various rules to be added to the rule group. By default, this pane is empty and is populated based on the actions you perform.

Files to be Allow listed pane

Displays the various files to be allow listed on the endpoint. By default, this pane is empty and is populated only when you choose the Add to Allow list action.

  • Add — Opens the Add to allow list dialog box. Specify the binary path name.

  • Remove — Deletes the selected rule.

  • Edit — Opens the Add to allow list dialog box with information for a selected rule. Edit the details as needed, then click OK.

Observations tab

Displays detailed information for observations in a tabular format.

Dismiss

Ignores the observation.

Approve

Saves the changes made and approve the observation.

Cancel

Exits without saving changes and return to the Observations (Deprecated) page.