Use queries to retrieve detailed information about the status of your managed systems and any threats in your environment. You can export, download, or combine queries into reports, and use queries as dashboard monitors.
Queries are questions that you ask Trellix ePO - On-prem., which returns answers as charts and tables. Reports enable you to package one or more queries into a single PDF document, for access outside of Trellix ePO - On-prem.
Similar information is available by accessing activity logs from the Trellix Endpoint Security (ENS) Client on individual systems.
You can view query data only for resources where you have permissions. For example, if your permissions grant access to a specific System Tree location, your queries return data only for that location.
Tip
Best practice: For information on how to create a report of which computers have an Extra.DAT file installed, see KB59410. For information on how to create a report for completed on-demand scans (event 1203), see KB69428.
Default queries
The module adds default queries to Trellix Groups. Depending on your permissions, you can use them as is, modify them, or create custom queries from events and properties in the Trellix ePO - On-prem database.
Endpoint Security Threat Prevention: Access Protection Compliance Status
Endpoint Security Threat Prevention: AMCore Content Compliance Status
Endpoint Security Threat Prevention: Applications with the Most Exploits in the Last 7 Days
Endpoint Security Threat Prevention: Content Status
Endpoint Security Threat Prevention: Detection Response Summary
Endpoint Security Threat Prevention: Duration of Completed Full Scans in the Last 7 Days
Endpoint Security Threat Prevention: Duration of Completed Quick Scans in the Last 7 Days
Endpoint Security Threat Prevention: Exploit Prevention Compliance Status
Endpoint Security Threat Prevention: Exploit Prevention Content Status
Endpoint Security Threat Prevention: False Positive Mitigation Events
Endpoint Security Threat Prevention: Hotfixes Installed
Endpoint Security Threat Prevention: On-Access Scan Compliance Status
Endpoint Security Threat Prevention: On-Access Scan McAfee GTI Sensitivity Level
Endpoint Security Threat Prevention: On-Demand Full Scan McAfee GTI Sensitivity Level
Endpoint Security Threat Prevention: On-Demand Quick Scan McAfee GTI Sensitivity Level
Endpoint Security Threat Prevention: Right-Click Scan McAfee GTI Sensitivity Level
Endpoint Security Threat Prevention: Systems Not Completed a Full Scan in the Last 7 Days
Endpoint Security Threat Prevention: Systems Not Completed a Full Scan in the Last Month
Endpoint Security Threat Prevention: Threat Count by Severity
Endpoint Security Threat Prevention: Threats Detected Over the Previous 2 Quarters
Endpoint Security Threat Prevention: Top 10 Access Protection Rules Broken
Endpoint Security Threat Prevention: Top 10 Computers with the Most Detections
Endpoint Security Threat Prevention: Top 10 Detected Threats
Endpoint Security Threat Prevention: Top 10 Exploits Prevented
Endpoint Security Threat Prevention: Top 10 Threat Sources
Endpoint Security Threat Prevention: Top 10 Threats per Threat Category
Endpoint Security Threat Prevention: Top 10 Users with the Most Detections
Custom queries (Trellix ePO - On-prem)
The module adds default properties to the Endpoint Security feature group. You can use these properties to create custom queries.
Feature Group | Result Type | Property (Column) | Property (Column) |
|---|---|---|---|
Endpoint Security | Endpoint Security Trellix ePO - On-prem Systems | Access Protection Additional Reasons | License Status |
Access Protection Compliance Status | Names of threats that Extra.DAT can detect | ||
Access Protection Enabled | On-Access Scan Additional Reason | ||
Access Protection Reason | On-Access Scan Compliance Status | ||
AMCore Content Additional Reasons | On-Access Scan Enabled | ||
AMCore Content Compliance Days | On-Access Scan Threat Prevention Sensitivity | ||
AMCore Content Compliance Status | On-Access Scan Reason | ||
AMCore Content Date | On-Demand Full Scan Date | ||
AMCore Content Reason | On-Demand Full Scan Duration (hours) | ||
AMCore Content Version | On-Demand Full Scan Threat Prevention Sensitivity | ||
AMCore Engine Version | On-Demand Quick Scan Date | ||
AMSI Enabled (Windows 10 and Windows Server 2016 systems only) | On-Demand Quick Scan Duration (minutes) | ||
AMSI Observe Mode Enabled (Windows 10 and Windows Server 2016 systems only) | On-Demand Quick Scan Threat Prevention Sensitivity | ||
AMSI supported by system | On-Demand Scan Additional Reasons | ||
AMSI supported by system reason | On-Demand Scan Compliance Status[a] | ||
DAT Version (Non-Windows) | On-Demand Scan Reason | ||
Exploit Prevention Additional Reasons | Right-Click Scan Trellix Sensitivity | ||
Exploit Prevention Compliance Status | ScriptScan Additional Reasons | ||
Exploit Prevention Content Created | ScriptScan Compliance Status | ||
Exploit Preventionontent Version | ScriptScan Enabled | ||
Exploit Prevention Enabled | ScriptScan Reason | ||
Exploit Prevention Reason | Threat Prevention Hotfix | ||
Language | Threat Prevention Patch Version | ||
Endpoint Security Platform Systems | Access Protection Debug Logging Enabled | On Access Scan Debug Logging Enabled | |
Access Protection Events Filter Level | On Access Scan Events Filter Level | ||
Exploit Prevention Debug Logging Enabled | On Demand Scan Debug Logging Enabled | ||
Exploit Prevention Events Filter Level | On Demand Scan Events Filter Level | ||
Events | Exploit Prevention Events | Access Requested | Source Port |
Action Taken | Source Process Hash | ||
Agent GUID | Source Process Signed | ||
AMCore Content Version | Source Process Signer | ||
Analyzer Content Creation Date | Source Share Name | ||
Analyzer Content Creation Version | Source Signed | ||
Analyzer Detection Method | Source Signer | ||
Analyzer Trellix Query | Source URL Rating Code | ||
Analyzer Reg Info | Source URL Web Category | ||
Analyzer Rule ID | Target Access Time | ||
Analyzer Rule Name | Target Create Time | ||
Analyzer Technology Version | Target Description | ||
API Name | Target Device Display Name | ||
Attack Vector Type | Target Device PID | ||
Cleanable | Target Device Serial Number | ||
DAT Version | Target Device VID | ||
Description | Target File Size (Bytes) | ||
Detecting Prod ID (deprecated) | Target Hash | ||
Detecting Product Host Name | Target Modify Time | ||
Detecting Product IP Address | Target Name | ||
Detecting Product IPv4 Address | Target Parent Process Hash | ||
Detecting Product MAC Address | Target Parent Process Name | ||
Detecting Product Name | Target Parent Process Signed | ||
Detecting Product Version | Target Parent Process Signer | ||
Direction | Target Path | ||
Duration Before Detection (Days) | Target Share Name | ||
Engine Version | Target Signed | ||
Event Category | Target Signer | ||
Event Generated Time | Target URL | ||
Event ID | Task Name | ||
Event Received Time | Threat Detected On Creation | ||
First Action Status | Threat Handled | ||
First Attempted Action | Threat Impact | ||
Location | Threat Name | ||
Module Name | Threat Severity | ||
Second Action Status | Threat Source Host Name | ||
Second Attempted Action | Threat Source IP Address | ||
Server ID | Threat Source IPv4 Address | ||
Source Access Time | Threat Source MAC Address | ||
Source Create Time | Threat Source Process Name | ||
Source Description | Threat Source URL | ||
Source Device Display Name | Threat Source User Name | ||
Source Device PID | Threat Target File Path | ||
Source Device Serial Number | Threat Target Host Name | ||
Source Device VID | Threat Target IP Address | ||
Source File Hash | Threat Target IPv4 Address | ||
Source File Path | Threat Target MAC Address | ||
Source File Size (Bytes) | Threat Target Network Protocol | ||
Source Modify Time | Threat Target Port Number | ||
Source Parent Process Hash | Threat Target Process Name | ||
Source Parent Process Name | Threat Target User Name | ||
Source Parent Process Signed | Threat Type | ||
Source Parent Process Signer | Topic | ||
[a] For information about queries and reports, see the Trellix ePO - On-prem documentation. A system is considered compliant for on-demand scans based on any of the following criteria:
| |||