Review details for an executable file. You can access this page when you click a row on the Policy Discovery page.
Option definitions
Options
Definition
Request Details
Lists properties for the selected file and the associated certificate information, if applicable.
File Name — Displays the name of the file. Also, clicking Lookup in TIE opens the TIE Reputations page that allows you to view or edit the file reputation.
File Version — Displays the version information for the file.
Path — Displays the full path of the file for which the request is received.
Parent Process — Displays the full path of the parent process that launched the file.
Files Changed — Lists the files modified in case of activities, such as File Addition.
Final Reputation — Displays the final reputation for the file.
File SHA-1 — Displays the SHA-1 value for the file. Click the value to find more details for the SHA-1, such as execution status and first seen information in inventory.
File SHA-256 — Displays the SHA-256 value for the file.
File MD5 — Displays the MD5 value for the file.
Application — Displays the name of the application associated with the file.
User Name — Displays the name of the user who sent the request.
Certificate — Displays the name of the certificate vendor. The color that the vendor is displayed in indicates whether the file is trusted (Green), malicious (Red), or unknown (Orange). Click the vendor name to review the following additional details. Also, clicking Lookup in TIE opens the TIE Certificate Reputations Details page that allows you to view or edit the certificate reputation.
Subject — Name of the certificate vendor.
Issuer — Name of the certificate signing authority.
Certificate Reputation — Reputation of the certificate. Possible values are Known Trusted, Most Likely Trusted, Might be Trusted, Unknown, Might be Malicious, Most Likely Malicious, and Known Malicious. The color in which the Certificate Reputation is displayed indicates whether the certificate is trusted (Green), malicious (Red), or unknown (Orange).
Reputation Source — Indicates the reputation source. Possible values are TIE and GTI.
Public Key Algorithm — Indicates the algorithm used to create the public key to encrypt messages.
Public Key Length — Specifies the length of the public key in bits.
Public Key Hash — Displays the public key hash.
Certificate Hash — Displays the certificate hash.
Valid From — Indicates the date from which the certificate is valid.
Valid To — Indicates the date until which the certificate is valid.
Enterprise Level Activity
Lists the individual requests that make up the collated request. These individual requests help you determine the file path and endpoint for the request.
Hide Filter/Show Filter — Hides or shows the filters in the pane.
Quick find — Specify the string to search for. You can search based on the host name.
Apply — Filters the request list based on the specified string.
Clear — Removes an applied filter.
Execution Time — Indicates the time when the policy discovery request was received.
Host Name — Displays the name of the host from which the request was received.
Description — Describes the action that has taken place on the endpoint.
Justification Message — Displays the comment or justification the user sent with the request.
Action — Displays the Allow Locally action for requests that are generated when you execute an application that is not in the allow list (Application Execution activity). This action adds one or more executable files to the allow list of an endpoint to allow the files to run on the endpoint.
Actions
Add Comments — Opens the Add Comments dialog box to record additional information for a request.
Allow File Globally — Adds rules to allow the file (based on SHA-1 ad SHA-256) to run across all endpoints in the enterprise. These rules are added to the Global Rules rule group included in the Trellix Default policy. When you allow requests, the selected collated requests and contained individual requests are all allowed.
Allow Trusted Path Globally — Adds rules to allow a file placed on a network path to run with updater privileges on all endpoints in the enterprise. Based on the network path associated with the request for which you want to define rules, suggested alternate paths (sorted based on path length) and corresponding number of matching requests for each suggested path are displayed. If needed, you can add rules for suggested alternate paths to allow all files placed on that network path and its subdirectories to run with updater privileges. These rules are added to the Global Rules rule group included in the Trellix Default policy.
Allow by Certificate Globally — Adds the certificate associated with the selected request with or without updater privileges. This allows all applications signed by the selected certificate to make changes to the executable files or launch any new application on the endpoints. These rules are added to the Global Rules rule group included in the Trellix Default policy. When you allow a request based on the associated certificate, the selected collated request and contained individual requests are allowed by certificate.
Ban File Globally — Adds rules to block the file (based on SHA-1 ad SHA-256) from running on any endpoint in the enterprise. These rules are added to the Global Rules rule group included in the Trellix Default policy. When you ban requests, the selected collated requests and contained individual requests are all blocked.
Bypass Memory Protection Globally — Adds rules to bypass applied memory-protection and other techniques for all endpoints.
Create Custom Policy — Opens the Policy Discovery: Custom Rules page. For selected endpoints, use this page to define custom rules to allow, block, or allow by certificate an application or executable file. Also, use this page to define custom rules to allow a network path.
Delete Requests — Removes the selected requests from the Policy Discovery page and database. When you delete requests, the selected collated requests and contained individual requests are deleted.
More — Click to access these actions.
Change File Reputation (TIE) — Opens the TIE Reputations page that displays reputation information for the file associated with the request. If needed, you can edit the file reputation.
View File Details — Opens the File Details page that displays detailed information for the file associated with the request.
View Related Events — Opens the Solidcore Events page that displays detailed information for the events associated with the request.
Close/Back — Closes the Policy Discovery Details page and returns to the Policy Discovery page.
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Interface Reference
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.3.x - Windows Product Guide > Using Application Control in Observe mode > Managing requests
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Using Application Control in Observe mode > Managing requests