Endpoint score refers to the average score calculated based on the number of devices (Windows and Linux) that have Endpoint Security installed. Consider the following criteria to optimize the posture score.
Content
Verifies the AMCore content version.
Features | Scoring | What to do? |
|---|---|---|
AMCore content insufficient for campaigns (specific to an individual campaign) | The current score is reduced by 1% if more than 50% of devices have outdated AMCore content. | AMCore content must be updated to latest version. |
AMCore content not updated |
| |
Devices not communicating with ePO | This feature does not affect the Endpoint score. | Establish communication with ePO by sending a Trellix Agent wake-up call. |
Zero-day
Analyzes the configuration and content associated with Adaptive Threat Protection and Real Protect.
Features | Scoring | What to do? |
|---|---|---|
RP Client not compliant (Windows only) | The current score is reduced by 1% if more than 20% of devices have RP Client disabled. | Make sure:
|
RP Cloud not compliant (Windows only) | The current score is reduced by 1% if more than 20% of devices have RP Cloud disabled. | Make sure:
|
Enhanced Script Scanning not enabled (Windows only) | The current score is reduced by 1% if more than 70% of devices have Enhanced Script Scanning disabled. | Make sure:
|
Credential Theft Protection not enabled (Windows only) | The current score is reduced by 1% if more than 95% of devices have Credential Theft Protection disabled. | Make sure:
|
Enhanced Remediation not enabled (Windows only) | The current score is reduced by 1% if more than 50% of devices have Enhanced Remediation disabled. | Make sure:
|
Configuration
Analyzes the configuration and content associated with On-Access Scan, On-Demand Scan, Access Protection, Exploit Prevention and Firewall.
On-Access Scan
Features
Scoring
What to do?
On-Access Scan not compliant
The current score is reduced by 1% if more than 20% of devices have On Access Scan disabled.
Make sure:
On Access Scan is enabled.
Action Enforcement is set to Delete or Clean.
Action Enforcement for Unwanted Programs
The current score is reduced by 1% if more than 95% of devices have Action Enforcement for Unwanted Programs detection disabled.
Make sure:
On Access Scan is compliant.
Action Enforcement is set to Delete or Clean for Unwanted Programs.
GTI not enabled
The current score is reduced by 1% if more than 50% of devices have GTI disabled.
Make sure:
On Access Scan is compliant.
GTI is enabled.
Scanning Config > Start Up Scan
(Windows only)
The current score is reduced by 1% if more than 70% of devices have System Start Up Scan disabled.
Make sure:
On Access Scan is compliant.
On-Access Scan is enabled on system startup.
Scanning Config > Network Copy
(Windows only)
The current score is reduced by 1% if more than 70% of devices have Network Copy disabled.
Make sure:
On Access Scan is compliant.
Scan when copying from network folders and removable drives is enabled.
Scanning Config > AMSI Compliant
(Windows only)
The current score is reduced by 1% if more than 70% of devices have AMSI disabled.
Make sure:
On Access Scan is compliant.
AMSI is enabled.
On-Demand Scan
Features
Scoring
What to do?
ODS Schedule Compliant
The current score is reduced by 1% if more than 70% of devices have On Demand Scan disabled.
Make sure:
A full system scan has been performed within the last 30 days.
Action Enforcement is set to Delete or Clean.
Action Enforcement for Unwanted Programs
The current score is reduced by 1% if more than 20% of devices have Unwanted Programs Detection disabled.
Action Enforcement must be set correctly for Unwanted Programs.
GTI not enabled
The current score is reduced by 1% if more than 50% of devices have GTI disabled.
GTI must be enabled.
Scan Config > Boot Sectors
(Windows only)
The current score is reduced by 1% if more than 70% of devices have Boot Sector scanning disabled.
Boot Sectors scan must be enabled.
Scan Config > Subfolders
The current score is reduced by 1% if more than 70% of devices have Subfolders scanning disabled.
Subfolders scan must be enabled.
Scan Config > Memory Root Kits
(Windows only)
The current score is reduced by 1% if more than 70% of devices have Memory Root Kits scanning disabled.
Memory Root Kits scan must be enabled.
Scan Config > Running Processes
(Windows only)
The current score is reduced by 1% if more than 70% of devices have Running Processes scanning disabled.
Running Processes scan must be enabled.
Scan Config > Local Drives
The current score is reduced by 1% if more than 70% of devices have Local Drives scanning disabled.
Local Drives scan must be enabled.
Scan Config > Windows Registry
(Windows only)
The current score is reduced by 1% if more than 70% of devices have Windows Registry disabled.
Windows Registry scan must be enabled.
Scan Config > File Types
The current score is reduced by 1% if more than 95% of devices have All Files Types scanning disabled.
File Types scan must be enabled.
Access Protection
Features
Scoring
What to do?
Compliance
The current score is reduced by 1% if more than 50% of devices have Access Protection disabled.
Access Protection scan must be enabled.
Rules
Make sure that the Windows-specific default set of rules are enabled. Deviating from the Windows-specific default set of rules is considered non-compliant.
Exploit Prevention
Features
Scoring
What to do?
Compliance
The current score is reduced by 1% if more than 50% of devices have Exploit Prevention disabled.
Exploit Prevention must be enabled.
Generic Privilege Escalation
(Windows only)
The current score is reduced by 1% if more than 70% of the devices have Generic Privilege Escalation disabled.
Generic Privilege Escalation Prevention must be enabled.
Windows Data Execution Prevention
(Windows only)
The current score is reduced by 1% if more than 70% of devices have Windows Data Execution Prevention disabled.
Windows Data Execution Prevention must be enabled.
Network Intrusion Prevention
(Windows only)
The current score is reduced by 1% if more than 70% of devices have Network Intrusion Prevention disabled.
Network Intrusion Prevention must be enabled.
Firewall
Features
Scoring
What to do?
Firewall not enabled
The current score is reduced by 1% if more than 70% of devices have firewall disabled.
The firewall must be enabled.
Detection Prevalence
Identifies the number of unresolved campaign-related events on devices based on the severity of the campaigns.
Features | Scoring | What to do? |
|---|---|---|
High Severity | List the devices with High Severity unresolved campaign detections. The current score is reduced by 1% if more than 5% of devices have unresolved campaign-related events. | AMCore content must be updated to latest version. |
Medium Severity | List the devices with Medium Severity unresolved campaign detections. The current score is reduced by 1% if more than 7% of devices have unresolved campaign-related events. | |
Low Severity | List the devices with Low Severity unresolved campaign detections. The current score is reduced by 1% if more than 10% of devices have unresolved campaign-related events. |
Vulnerability assessment
Identifies the number of unresolved campaign detections and their associated CVEs in your environment.
Severity level | Scoring | What to do? |
|---|---|---|
Critical | Unresolved CVEs with Critical severity levels are listed. The current score is reduced by 1% if more than 5% of the CVEs detected are in this level. | CVEs detected must be mitigated to improve the security posture score. |
High | Unresolved CVEs with High severity levels are listed. The current score is reduced by 1% if more than 7% of the CVEs detected are in this level. | |
Medium | Unresolved CVEs with Medium and Low severity levels are listed. The current score is reduced by 1% if more than 10% of the CVEs detected are in these levels. | |
Low |