Capability descriptions

Prev Next

The following table describes the functionality provided by each capability.

Capability

Description

Alerts

Ability to annotate or acknowledge alerts, which indicate the detection of malware.

Alerts (view)

Read-only access to the "Alerts" functionality. If a subnet is configured on the local account, the view could be filtered by subnet.

All Users

Commands and functionality available to users in all roles (except API Analyst and API Monitor).

Analysis

Ability to analyze malware.

Analysis (view)

Read-only access to "Analysis" functionality.

Audit Logs

Ability to view audit logs, but not system logs.

Authentication (AAA)

Configuration of authentication, authorization, and accounting (AAA).

Authentication (AAA) (view)

Read-only access to "Authentication (AAA)" functionality.

CM Series

Ability to configure managed appliances and appliance records remotely.

Note

The "CM Series" capabilities are available only on the Central Management System appliance.

CM Series (view)

Read-only access to "CM Series" functionality.

CM Series Client (LMS)

Management of appliances by the Central Management System appliance. (A managed appliance is also known as a client or LMS.)

CM Series Client (LMS) (view)

Read-only access to "CM Series Client (LMS)" functionality.

CM Series Proxy

Ability to fully control remote managed appliances both by executing commands remotely from the Central Management System appliance and by sending proxied actions and queries.

CM Series Proxy (view)

Read-only access to "CM Series Proxy" functionality.

Crypto

Management of cryptological functions such as Internet Protocol Security (IPsec) and certificates.

Crypto (view)

Read-only access to "Crypto" functionality. Sensitive information such as private keys may be obfuscated.

Detection

Management of system configuration and data that affect malware detection efficacy, such as downloading and managing guest images and security content.

Detection (view)

Read-only access to "Detection" functionality.

Diagnostics

Access to diagnostic tools such as debug dumps (sysdumps), ping, and traceroute.

Trellix Database (fedb)

Management of the Trellix database, such as backing it up and restoring it.

Trellix Database (fedb) (view)

Read-only access to "Trellix Database (fedb)" functionality.

Health

Ability to view summary information about current system status. (Detailed information is available with the "System (view)" capability.)

Licenses

Management of license keys.

Licenses (view)

Read-only access to "Licenses" functionality.

Manage Own Account

Ability to change one's own local account password and to manage local SSH client functionality (authorized keys, identities, and known hosts) for one's own local account.

Note

This functionality is available only to locally authenticated users; that is, users who were authenticated using the configuration they are now attempting to change. Remotely authenticated users cannot change local account information, even if they are mapped to the same or a different local user name.

Monitor Legacy

Functionality that the "monitor" capability had prior to the introduction of roles, which is not permitted according to the strict interpretation of the "monitor" role.

Network

Ability to manage network configuration, such as interfaces and routers.

Network (view)

Read-only access to "Network" functionality.

Notifications

Ability to configure user notifications about malware-related events (such as alerts) and system-related events (such as low disk space).

Notifications (view)

Read-only access to "Notifications" functionality.

Reports

Ability to generate reports.

Reports (view)

Read-only access to "Reports" functionality, such as viewing generated reports.

Stats

Ability to manage statistics.

Stats (view)

Read-only access to "Stats" functionality.

System

General system administration functions.

System Admin

Both general system administration functions and sensitive functions that require a higher level of authorization.

System (view)

Read-only access to the "System" and "System Admin" functionality.

System Logs

Ability to read system logs, but not audit logs.