Analyze the suggestions available for an observation and take actions.
Option | Definition | |
|---|---|---|
Binary Tree | Represents the hierarchy and relationship between the file and its parent process. Also, allows you to review information for all child observations associated with the opened collated observation. By default, the file associated with the collated observation is selected in this pane. | |
Suggestions tab | Binary Info pane | Displays detailed information for the selected binary file and lists all actions you can perform for the file. Depending on the file's properties and attributes, one or more of the following actions are available for the file.
|
Certificate Info pane | Displays information for the certificate, if any, associated with the file. This pane is displayed only if a certificate is associated with the selected file.
| |
Rule Group pane | Displays the various rules to be added to the rule group. By default, this pane is empty and is populated based on the actions you perform. | |
Files to be Allow listed pane | Displays the various files to be allow listed on the endpoint. By default, this pane is empty and is populated only when you choose the Add to Allow list action.
| |
Observations tab | Displays detailed information for observations in a tabular format. | |
Dismiss | Ignores the observation. | |
Approve | Saves the changes made and approve the observation. | |
Cancel | Exits without saving changes and return to the Observations (Deprecated) page. | |