Endpoint score calculation

Prev Next

Endpoint score refers to the average score calculated based on the number of devices (Windows and Linux) that have Endpoint Security installed. Consider the following criteria to optimize the posture score.

Content

Verifies the AMCore content version.

Features

Scoring

What to do?

AMCore content insufficient for campaigns (specific to an individual campaign)

The current score is reduced by 1% if more than 50% of devices have outdated AMCore content.

AMCore content must be updated to latest version.

AMCore content not updated

  • If you have not updated your AMCore content within 3 days, the current score varies between 0 and 100%.

  • Your current score is reduced by 1% if more than 50% of devices have outdated AMCore content and no updates have been made within 7 days.

  • Your current score is reduced by 1% if more than 20% of devices have outdated AMCore content and no updates have been made within 30 days.

Devices not communicating with ePO

This feature does not affect the Endpoint score.

Establish communication with ePO by sending a Trellix Agent wake-up call.

Zero-day

Analyzes the configuration and content associated with Adaptive Threat Protection and Real Protect.

Features

Scoring

What to do?

RP Client not compliant

(Windows only)

The current score is reduced by 1% if more than 20% of devices have RP Client disabled.

Make sure:

  1. ATP is installed and enabled.

  2. ATP is not in the observe mode.

  3. RP Client is enabled.

  4. Action Enforcement is set to Block and Clean for known-malicious reputation or lower.

RP Cloud not compliant

(Windows only)

The current score is reduced by 1% if more than 20% of devices have RP Cloud disabled.

Make sure:

  1. ATP is installed and enabled.

  2. ATP is not in the observe mode.

  3. RP Cloud is enabled.

  4. Action Enforcement is set to Block and Clean for known-malicious reputation or lower.

Enhanced Script Scanning not enabled

(Windows only)

The current score is reduced by 1% if more than 70% of devices have Enhanced Script Scanning disabled.

Make sure:

  1. RP Client is compliant.

  2. Enhanced Script Scanning is enabled.

Credential Theft Protection not enabled

(Windows only)

The current score is reduced by 1% if more than 95% of devices have Credential Theft Protection disabled.

Make sure:

  1. ATP is installed and enabled.

  2. ATP is not in the observe mode.

  3. Credential Theft Protection is enabled.

Enhanced Remediation not enabled

(Windows only)

The current score is reduced by 1% if more than 50% of devices have Enhanced Remediation disabled.

Make sure:

  1. RP Client or RP Cloud is compliant.

  2. Enhanced Remediation is enabled.

Configuration

Analyzes the configuration and content associated with On-Access Scan, On-Demand Scan, Access Protection, Exploit Prevention and Firewall.

  • On-Access Scan

    Features

    Scoring

    What to do?

    On-Access Scan not compliant

    The current score is reduced by 1% if more than 20% of devices have On Access Scan disabled.

    Make sure:

    1. On Access Scan is enabled.

    2. Action Enforcement is set to Delete or Clean.

    Action Enforcement for Unwanted Programs

    The current score is reduced by 1% if more than 95% of devices have Action Enforcement for Unwanted Programs detection disabled.

    Make sure:

    1. On Access Scan is compliant.

    2. Action Enforcement is set to Delete or Clean for Unwanted Programs.

    GTI not enabled

    The current score is reduced by 1% if more than 50% of devices have GTI disabled.

    Make sure:

    1. On Access Scan is compliant.

    2. GTI is enabled.

    Scanning Config > Start Up Scan

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have System Start Up Scan disabled.

    Make sure:

    1. On Access Scan is compliant.

    2. On-Access Scan is enabled on system startup.

    Scanning Config > Network Copy

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have Network Copy disabled.

    Make sure:

    1. On Access Scan is compliant.

    2. Scan when copying from network folders and removable drives is enabled.

    Scanning Config > AMSI Compliant

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have AMSI disabled.

    Make sure:

    1. On Access Scan is compliant.

    2. AMSI is enabled.

  • On-Demand Scan

    Features

    Scoring

    What to do?

    ODS Schedule Compliant

    The current score is reduced by 1% if more than 70% of devices have On Demand Scan disabled.

    Make sure:

    1. A full system scan has been performed within the last 30 days.

    2. Action Enforcement is set to Delete or Clean.

    Action Enforcement for Unwanted Programs

    The current score is reduced by 1% if more than 20% of devices have Unwanted Programs Detection disabled.

    Action Enforcement must be set correctly for Unwanted Programs.

    GTI not enabled

    The current score is reduced by 1% if more than 50% of devices have GTI disabled.

    GTI must be enabled.

    Scan Config > Boot Sectors

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have Boot Sector scanning disabled.

    Boot Sectors scan must be enabled.

    Scan Config > Subfolders

    The current score is reduced by 1% if more than 70% of devices have Subfolders scanning disabled.

    Subfolders scan must be enabled.

    Scan Config > Memory Root Kits

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have Memory Root Kits scanning disabled.

    Memory Root Kits scan must be enabled.

    Scan Config > Running Processes

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have Running Processes scanning disabled.

    Running Processes scan must be enabled.

    Scan Config > Local Drives

    The current score is reduced by 1% if more than 70% of devices have Local Drives scanning disabled.

    Local Drives scan must be enabled.

    Scan Config > Windows Registry

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have Windows Registry disabled.

    Windows Registry scan must be enabled.

    Scan Config > File Types

    The current score is reduced by 1% if more than 95% of devices have All Files Types scanning disabled.

    File Types scan must be enabled.

  • Access Protection

    Features

    Scoring

    What to do?

    Compliance

    The current score is reduced by 1% if more than 50% of devices have Access Protection disabled.

    Access Protection scan must be enabled.

    Rules

     

    Make sure that the Windows-specific default set of rules are enabled. Deviating from the Windows-specific default set of rules is considered non-compliant.

  • Exploit Prevention

    Features

    Scoring

    What to do?

    Compliance

    The current score is reduced by 1% if more than 50% of devices have Exploit Prevention disabled.

    Exploit Prevention must be enabled.

    Generic Privilege Escalation

    (Windows only)

    The current score is reduced by 1% if more than 70% of the devices have Generic Privilege Escalation disabled.

    Generic Privilege Escalation Prevention must be enabled.

    Windows Data Execution Prevention

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have Windows Data Execution Prevention disabled.

    Windows Data Execution Prevention must be enabled.

    Network Intrusion Prevention

    (Windows only)

    The current score is reduced by 1% if more than 70% of devices have Network Intrusion Prevention disabled.

    Network Intrusion Prevention must be enabled.

  • Firewall

    Features

    Scoring

    What to do?

    Firewall not enabled

    The current score is reduced by 1% if more than 70% of devices have firewall disabled.

    The firewall must be enabled.

Detection Prevalence

Identifies the number of unresolved campaign-related events on devices based on the severity of the campaigns.

Features

Scoring

What to do?

High Severity

List the devices with High Severity unresolved campaign detections.

The current score is reduced by 1% if more than 5% of devices have unresolved campaign-related events.

AMCore content must be updated to latest version.

Medium Severity

List the devices with Medium Severity unresolved campaign detections.

The current score is reduced by 1% if more than 7% of devices have unresolved campaign-related events.

Low Severity

List the devices with Low Severity unresolved campaign detections.

The current score is reduced by 1% if more than 10% of devices have unresolved campaign-related events.

Vulnerability assessment

Identifies the number of unresolved campaign detections and their associated CVEs in your environment.

Severity level

Scoring

What to do?

Critical

Unresolved CVEs with Critical severity levels are listed.

The current score is reduced by 1% if more than 5% of the CVEs detected are in this level.

CVEs detected must be mitigated to improve the security posture score.

High

Unresolved CVEs with High severity levels are listed.

The current score is reduced by 1% if more than 7% of the CVEs detected are in this level.

Medium

Unresolved CVEs with Medium and Low severity levels are listed.

The current score is reduced by 1% if more than 10% of the CVEs detected are in these levels.

Low