The following table describes the functionality provided by each capability.
Capability | Description |
|---|---|
Alerts | Ability to annotate or acknowledge alerts, which indicate the detection of malware. |
Alerts (view) | Read-only access to the "Alerts" functionality. If a subnet is configured on the local account, the view could be filtered by subnet. |
All Users | Commands and functionality available to users in all roles (except API Analyst and API Monitor). |
Analysis | Ability to analyze malware. |
Analysis (view) | Read-only access to "Analysis" functionality. |
Audit Logs | Ability to view audit logs, but not system logs. |
Authentication (AAA) | Configuration of authentication, authorization, and accounting (AAA). |
Authentication (AAA) (view) | Read-only access to "Authentication (AAA)" functionality. |
CM Series | Ability to configure managed appliances and appliance records remotely. NoteThe "CM Series" capabilities are available only on the Central Management System appliance. |
CM Series (view) | Read-only access to "CM Series" functionality. |
CM Series Client (LMS) | Management of appliances by the Central Management System appliance. (A managed appliance is also known as a client or LMS.) |
CM Series Client (LMS) (view) | Read-only access to "CM Series Client (LMS)" functionality. |
CM Series Proxy | Ability to fully control remote managed appliances both by executing commands remotely from the Central Management System appliance and by sending proxied actions and queries. |
CM Series Proxy (view) | Read-only access to "CM Series Proxy" functionality. |
Crypto | Management of cryptological functions such as Internet Protocol Security (IPsec) and certificates. |
Crypto (view) | Read-only access to "Crypto" functionality. Sensitive information such as private keys may be obfuscated. |
Detection | Management of system configuration and data that affect malware detection efficacy, such as downloading and managing guest images and security content. |
Detection (view) | Read-only access to "Detection" functionality. |
Diagnostics | Access to diagnostic tools such as debug dumps (sysdumps), ping, and traceroute. |
Trellix Database (fedb) | Management of the Trellix database, such as backing it up and restoring it. |
Trellix Database (fedb) (view) | Read-only access to "Trellix Database (fedb)" functionality. |
Health | Ability to view summary information about current system status. (Detailed information is available with the "System (view)" capability.) |
Licenses | Management of license keys. |
Licenses (view) | Read-only access to "Licenses" functionality. |
Manage Own Account | Ability to change one's own local account password and to manage local SSH client functionality (authorized keys, identities, and known hosts) for one's own local account. NoteThis functionality is available only to locally authenticated users; that is, users who were authenticated using the configuration they are now attempting to change. Remotely authenticated users cannot change local account information, even if they are mapped to the same or a different local user name. |
Monitor Legacy | Functionality that the "monitor" capability had prior to the introduction of roles, which is not permitted according to the strict interpretation of the "monitor" role. |
Network | Ability to manage network configuration, such as interfaces and routers. |
Network (view) | Read-only access to "Network" functionality. |
Notifications | Ability to configure user notifications about malware-related events (such as alerts) and system-related events (such as low disk space). |
Notifications (view) | Read-only access to "Notifications" functionality. |
Reports | Ability to generate reports. |
Reports (view) | Read-only access to "Reports" functionality, such as viewing generated reports. |
Stats | Ability to manage statistics. |
Stats (view) | Read-only access to "Stats" functionality. |
System | General system administration functions. |
System Admin | Both general system administration functions and sensitive functions that require a higher level of authorization. |
System (view) | Read-only access to the "System" and "System Admin" functionality. |
System Logs | Ability to read system logs, but not audit logs. |