View all Solidcore events generated for the managed endpoints.
Option | Definition | |
|---|---|---|
Filter | Filters the displayed events based on specified criteria, including:
| |
What's reputation-based execution? | Opens a Trellix KnowledgeBase article that explains reputation-based execution. | |
Deny Reason | Displays the reason for denial for Execution Denied events. | |
Value | Description | |
Application Control Policy - File banned by name | Application Control blocked this file because a ban rule exists for the file. | |
Application Control Policy - File banned by SHA-1 | Application Control blocked this file because a ban rule exists for the SHA-1 of the file. | |
Application Control Policy - File execution denied by user | Application Control blocked this file because its execution was denied by the user. | |
TIE - Malicious process SHA-1 | Application Control blocked this file because the file reputation received from the TIE server is malicious or because Trellix Sandboxing technology (ATD) analyzed it to be suspicious. | |
GTI - Malicious process SHA-1 | Application Control blocked this file because the file reputation received from the GTI server is malicious. | |
TIE - Malicious Certificate | Application Control blocked this file because the reputation received for the associated certificate from the TIE server is malicious. | |
GTI - Malicious Certificate | Application Control blocked this file because the reputation received for the associated certificate from the GTI server is malicious. | |
Local Allow list- File not present in allow list | Application Control blocked this file because it is not allow listed. To execute this file, add the file to the allow list. | |
Application Control Policy - Network path not trusted | Application Control blocked this file because it was executed from a non-trusted network path. | |
Application Control Policy - Removable media not trusted | Application Control blocked this file because it was executed from a non-trusted media. | |
Local Allow list- File SHA-1 mismatch | Application Control blocked this file because the file's checksum in not present in the inventory. This can occur if the file SHA-1 changed. | |
Reputation (at Time of Execution) | Displays the reputation of the file on the endpoint at the time of execution. This value is applicable only for the Execution Denied events where execution is denied due to malicious reputation. Possible values include TIE Malicious Certificate, GTI Malicious Certificate, TIE Malicious Checksum, GTI Malicious Checksum, and Not Applicable. | |
Actions | Specifies the actions that you can perform on the selected events, including:
| |
User Comments | Displays the Add a comment link where you can record additional information for an event. | |
Select all in this page | Selects all Solidcore events listed on the current page. | |
Select all in all pages | Selects all Solidcore events displayed on all pages. | |