View all requests received from endpoints in the enterprise, and define rules to manage the requests.
Option definitions
Options | Definition |
|---|
Filters | Filter the displayed requests based on specified criteria. Time Filter — Filters requests generated in the specified time period. Approval Status — Filters requests based on their approval status. Activity — Filters requests generated for the specified activity. Here is a description of the activities.
|
ActiveX Installation | Installation of a non-allow listed ActiveX control signed by the certificate (listed in the Object Name column). |
Application Execution | Non-allow listed executable file (listed in the Object Name column) is executed. |
Application Execution at Start Up | Boot time execution allowed for a non-allow listed executable file (listed in the Object Name column). |
File Addition | New file (listed in the Object Name column) generated by a non-trusted agent on the endpoint. |
File Modification | Allow listed application (listed in the Object Name column) modified by a non-trusted agent. |
File Update at Start Up | Executable file (listed in the Object Name column) tried to update an allow listed file at boot time. |
Memory Protection Violation | Allow listed executable file (listed in the Object Name column) tried a memory-protection (NX, CASP, or VASR) violation. |
Network path execution | File placed on a network path (listed in the Object Name column) is executed. |
Script Execution | Non-allow listed script file (listed in the Object Name column) is executed. |
Software Installation | Application installation by a non-allow listed executable file or Microsoft Installer (MSI) (listed in the Object Name column). |
Software Uninstallation | Application uninstallation of an allow listed executable file or MSI (listed in the Object Name column). |
Final Reputation — Filters requests based on the file's reputation. System Name — Filters requests generated for the specified endpoint. Update Results — Applies the selected filters and displays requests that match the specified criteria. Reset Filters — Removes all filters. Additional Filters/Hide Filters — Shows or hides additional filters in the pane. What's Final Reputation? — Opens a Trellix KnowledgeBase article that explains how the software determines final reputation for files or certificates. Hide Filter/Show Filter — Hides or shows the filters in the pane. Quick find — Specifies the string to search for. You can search based on the object name, application name, and certificate. Apply — Filters the requests list based on the specified string. Clear — Removes an applied filter. Show selected rows — Hides all rows except the rows selected on the page.
|
Object Name | Displays the name of the file that was executed or acted on. Hover on the object name to view or copy the content. |
Final Reputation | Displays the enterprise reputation for files. The color that the enterprise reputation is displayed in indicates whether the file is trusted, malicious, or unknown. |
Color | Reputation |
Green | Known Trusted |
Most Likely Trusted |
Might be Trusted |
Orange | Unknown |
Red | Might be Malicious |
Most Likely Malicious |
Known Malicious |
Gray | Not applicable (only for network path execution requests) |
Reputation Source | Displays the reputation source for files, such as TIE, GTI, Application Control, Not synchronized, or Not Applicable. If the reputation source is TIE, clicking TIE opens the TIE Reputations page that allows you to view details for the selected file. Values of TIE, GTI, or Application Control indicate the source last synchronized with. Not synchronized indicates that the software has not synchronized with any reputation source. For network path execution requests, reputation source is set to Not applicable. |
Certificate | Displays the certificate associated with the file. Hover on the certificate name to view or copy the public key hash and certificate hash. |
Global Prevalence | Lists the count of the requests received for a file. After requests are received from the endpoints, Application Control collates and groups requests based on these parameters: Memory protection violation requests are grouped based on SHA-1 and activity type. Network path execution requests are grouped based on file path and activity type.
|
Our Comments | Displays the additional information recorded for a request. |
Actions | Add Comments — Opens the Add Comments dialog box where you can record additional information for multiple requests. Allow File Globally — Adds rules to allow the executable file (based on SHA-1 and SHA-256) to run across all endpoints in the enterprise. These rules are added to the Global Rules rule group included in the Trellix Default policy. When you allow requests, the selected collated requests and contained individual requests are all allowed. Allow Trusted Path Globally — Adds rules to allow a file placed on a network path to run with updater privileges on all endpoints in the enterprise. Based on the network path associated with the request for which you want to define rules, suggested alternate paths (sorted by path length) and corresponding number of matching requests for each suggested path are displayed. If needed, you can add rules for suggested alternate paths to allow all files placed on that network path and its subdirectories to run with updater privileges on all endpoints in the enterprise. These rules are added to the Global Rules rule group included in the Trellix Default policy. Allow by Certificate Globally — Adds the certificate associated with the selected request with or without updater privileges. This allows all applications signed by the selected certificate to change the executable files or start any new application on the endpoints. These rules are added to the Global Rules rule group included in the Trellix Default policy. When you allow a request based on the associated certificate, the selected collated request and contained individual requests are allowed by certificate. Ban File Globally — Adds rules to block the executable file (based on SHA-1 and SHA-256) from running on any endpoint in the enterprise. These rules are added to the Global Rules rule group included in the Trellix Default policy. When you ban requests, the selected collated requests and contained individual requests are all blocked. Bypass Memory Protection Globally — Adds rules to bypass applied memory-protection and other techniques for all endpoints. Choose Columns — Opens the Select the Columns to Display page. Use this to select the columns of data to display on the Policy Discovery page. Create Custom Policy — Opens the Policy Discovery: Custom Rules page. Use this page to define custom rules to allow, block, or allow by certificate an application or executable file for selected endpoints. Also, use this page to define custom rules to allow a network path for selected endpoints. Delete Requests — Removes the selected requests from the Policy Discovery page and database. When you delete requests, the selected collated requests and contained individual requests are deleted. Export Table — Opens the Export page. Use this page to specify the format and package of files export. You can save or email the requests list. More — Click to access these options. Change File Reputation (TIE) — Opens the TIE Reputations page that displays reputation information for the file associated with the request. If needed, you can edit the file reputation. View File Details — Opens the File Details page that displays detailed information for the file associated with the request. View Related Events — Opens the Solidcore Events page that displays detailed information for the events associated with the request.
|