Threats — Your Environment

Prev Next

On the Threats Overview page, select Your Environment to view how the threat has affected devices in your organization.

Item

Description

Detections Timeline

View the number of events for the threat in the organization along a timeline.

Select Last day, Last week , or Last month to change the scale of the timeline.

Your ENS Devices

For Endpoint Security threats only, the Your Environment page does not display the Your Network (NSP) table (below).

Select these tabs to view a list of devices in your environment.

  • Devices Exposed — View devices where the campaign event is not remediated.

  • Devices with insufficient coverage — View devices that do not have the minimum AMCore Content version.

    Note

    Using device exclusion rules to stop particular endpoint devices from being flagged for insufficient content or coverage affects the number of devices displayed under this tab.

  • All Impacted Devices — View all devices that have IoCs for this campaign.

For each device you can view the following:

  • System Name — Click to view the system in the System Tree.

  • IP Address

  • Last communicated

  • Resolved Detections

  • Unresolved Detections

  • Last detected

  • Issues

Your Network (NSP)

For network threats only, the Your Environment page does not display the Your ENS Devices table (above).

For each device you can view the following:

  • Attack Type

  • Category

  • Sub-Category

  • Protocol

  • Blocking

  • Count

  • Mark as Resolved

Event Details — Your ENS Devices

Click a System name to view event details for a device.

Item

Description

System name

View the name of the selected system. Click to view the system in the System Tree.

Detection Timeline

Select an option to view events by timeline.

Detection Date

View the detection date.

Search

Use search to filter the list of events.

Events

View a list of events and the time stamp of the event.

Details

View details of the event:

  • Product Details

    • Product Name

    • Product Version

    • AMCore Content Version

  • File Details

    • File Path

  • Detection Details

    • Resolution

    • Detection

  • Mark this event as resolved - Trellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the timestamp, and additional comments.

  • Process Trace - Process tracing displays details for processes executed on your endpoints in graph format. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information.

Event Details — Your Network (NSP)

Click to view event details of the device.

Item

Description

Detection Timeline

Select an option to view events by timeline.

Detection Date

View the detection date.

Search

Use search to filter the list of events.

Events

View a list of Events and the time stamp of the event.

Details

View details of the event:

  • Product Details

    • Product Name

    • Product Version

  • Execution Details

    • Application Name

    • Direction of attack

    • NSP Protocol

    • Source IP address

    • Source Port

    • Source DNS Name

    • Destination IP address

    • Destination Port

    • Destination DNS Name

  • Direction Details

    • Attack Name

    • Attack Type

    • Detection Mechanism

    • Category

    • Sub-Category

    Mark this event as resolved - Trellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the timestamp, and additional comments.