View a comprehensive list of devices impacted by campaigns and threats. The list includes devices which are currently vulnerable to attack, or are not correctly configured based on your security posture score.
This page is accessible by clicking a device or detection count found in several locations in the user interface. These locations include:
Security Posture Score— Device count against each element.
Campaign Detections — Total detection count.
Devices — Exposed devices and insufficient coverage devices count.
Campaigns table — Exposed devices, insufficient coverage, resolved, and unresolved detections.
Threats table — All impacted devices and total detections.
Clicking a device displays all events detected on that device.
Item | Description |
|---|---|
Filters | Select to filter devices based on the following criteria:
|
Devices | For each device you can view the following details:
Click a row or System Name to view events on the device and its policy details. The Actions button in the drawer also provides an option to view the device in the System Tree. |
Event and policy details
View all events and policy details for a particular device.
Item | Description |
|---|---|
Filter | Search or select an option to view a subset of the events.
|
Event Details | View a list of events with the following information: File Name
Click an event to expand the view: Event Details
Basic Properties
Detection Details
Mark this event as resolved - Trellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the timestamp, and additional comments. Mark all as resolved - Trellix Insights allows you to resolve multiple events for a device.
Process Trace - Process tracing displays details for processes executed on your endpoints in graph format. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information. |
Policy Details This tab groups violations by ePO policy. For example, all violations in the Zero-Day category map to the ePO Endpoint Security Adaptive Threat Protection policy. | View a list of events with the following information: File Name
Click an event to expand the view: Event Details
Basic Properties
Detection Details
Mark this event as resolved - Trellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the timestamp, and additional comments. Process Trace - Process tracing displays details for processes executed on your endpoints in graph format. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information. |