Any action to change or execute an unauthorized file or program on a protected system causes Application Control to prevent the action and generate a corresponding event on the endpoint.
All events for managed systems are sent to the ePO - SaaS server. You can review and manage the generated events to monitor the status of the managed endpoints.
Solidcore Events severity is classified as Info, Minor, Warning, Major, Critical, and Fatal. This classification is done based on the ePO - SaaS common threat event severity, numbered from 1–7.
Note
Categories such as Info, Minor, Warning, Major, Critical, and Fatal are displayed on the Threat Events Log page. The severity is displayed in numbers on the Solidcore Events page.
Windows Event viewer is categorized as:
Information — Info, Minor
Warning — Warning
Error — Major, Critical, Fatal
When an event is generated, Solidcore Events severity is classified as Info, Minor, Warning, Major, Critical, or Fatal. When it is mapped with Windows Event categories, ePO - SaaS Severity is tagged as Information, Warning, or Error.
TACC 9.x.x supports the following denial events:
Execution Denied
Registry Write Denied
File Write Denied
Inventory Corrupted
Data Dropped
Installation Denied
Data Throttled