Based on the threat events reported and files executed on a system, you can set its health status to see compromised systems and healthy systems.
As events are reported and files are blocked or allowed, you can set the health status of specific systems. You can then monitor compromised systems for threat events, or change policy settings for systems that have run, or often block, malicious or suspicious files.
There are three settings for system health status: Compromised, Healthy, and Possibly Compromised. You can manually set the health status for particular systems using Threat Intelligence Exchange, or create an automatic response query or server task in ePO - On-prem to apply a status automatically. You can then create a query that looks for compromised systems and run a server task to take a specific action on those systems.
When creating the automatic response in ePO - On-prem, the system health status options are on the Actions page of the wizard. Choose the Run System Command action, and from the System command drop-down, choose Set System Health Indicator and specify the health status.
For details about creating automatic responses, queries, and server tasks, see Trellix ePolicy Orchestrator - On-premises Best Practices Guide.