On the Threats Overview page, select Your Environment to view how the threat has affected devices in your organization.
Item
Description
Detections Timeline
View the number of events for the threat in the organization along a timeline.
Select Last day, Last week , or Last month to change the scale of the timeline.
Your ENS Devices
For Endpoint Security threats only, the Your Environment page does not display the Your Network (NSP) table (below).
Select these tabs to view a list of devices in your environment.
Devices Exposed — View devices where the campaign event is not remediated.
Devices with insufficient coverage — View devices that do not have the minimum AMCore Content version.
Note
Using device exclusion rules to stop particular endpoint devices from being flagged for insufficient content or coverage affects the number of devices displayed under this tab.
All Impacted Devices — View all devices that have IoCs for this campaign.
For each device you can view the following:
System Name — Click to view the system in the System Tree.
IP Address
Last communicated
Resolved Detections
Unresolved Detections
Last detected
Issues
Your Network (NSP)
For network threats only, the Your Environment page does not display the Your ENS Devices table (above).
For each device you can view the following:
Attack Type
Category
Sub-Category
Protocol
Blocking
Count
Mark as Resolved
Event Details — Your ENS Devices
Click a System name to view event details for a device.
Item
Description
System name
View the name of the selected system. Click to view the system in the System Tree.
Detection Timeline
Select an option to view events by timeline.
Detection Date
View the detection date.
Search
Use search to filter the list of events.
Events
View a list of events and the time stamp of the event.
Details
View details of the event:
Product Details
Product Name
Product Version
AMCore Content Version
File Details
File Path
Detection Details
Resolution
Detection
Mark this event as resolved - Trellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the timestamp, and additional comments.
Process Trace - Process tracing displays details for processes executed on your endpoints in graph format. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information.
Event Details — Your Network (NSP)
Click to view event details of the device.
Item
Description
Detection Timeline
Select an option to view events by timeline.
Detection Date
View the detection date.
Search
Use search to filter the list of events.
Events
View a list of Events and the time stamp of the event.
Details
View details of the event:
Product Details
Product Name
Product Version
Execution Details
Application Name
Direction of attack
NSP Protocol
Source IP address
Source Port
Source DNS Name
Destination IP address
Destination Port
Destination DNS Name
Direction Details
Attack Name
Attack Type
Detection Mechanism
Category
Sub-Category
Mark this event as resolved - Trellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the timestamp, and additional comments.