Seven attack definitions are added to the NTBA policies in Policy → Network Threat Behavior Analysis → NTBA Policies:
| NTBA policy | Description | Enabled by default | Alert frequency |
|---|---|---|---|
| EXECUTABLE: Unclassified executable detected by Endpoint Intelligence Agent engine | This alert is raised when the executable is not classified by the administrator or is not auto-classified. | No | Raised once per executable from the NTBA Appliance |
| EXECUTABLE: Allowed executable detected by Endpoint Intelligence Agent engine | This alert is raised when the executable is marked as
allowed by the administrator.
This alert is also raised when the executable is found to be digitally allowed or GTI allowed. |
No | |
| EXECUTABLE: Blocked executable detected by Endpoint Intelligence Agent engine | This alert is raised when the executable is marked as blocked by the administrator or when the executable is auto-classified based on GTI Block List. | Yes | Raised per executable per endpoint |
| MALWARE: Very High-confidence malware executable detected by Endpoint Intelligence Agent engine | This alert is raised when the malware confidence of the executable detected by McAfee EIA is very high and the executable is not allowed. | Yes | |
| MALWARE: High-confidence malware executable detected by Endpoint Intelligence Agent engine | This alert is raised when the malware confidence of the executable detected by McAfee EIA is high and the executable is not allowed. | Yes | |
| MALWARE: Medium-confidence malware executable detected by Endpoint Intelligence Agent engine | This alert is raised when the malware confidence of the executable detected by McAfee EIA is medium and the executable is not allowed. | No | |
| MALWARE: Very High-confidence malware file detected by Endpoint Intelligence Agent engine | This alert is raised when the malware confidence of the file detected by McAfee EIA is very high and the file is not allowed. | No | Raised per non-executable file such as doc or pdf file per endpoint |
Depending on which of the attack definitions are enabled in the NTBA policies, alerts are generated for the matching traffic.
The malware attacks can be viewed in the Top Malware Files monitor on the Manager Dashboard page, and the Top Attack Executables table in the Threat Explorer.
Alert throttling
Run set endpointintelligence alertinterval CLI command to configure the time interval as to when the alert should be raised again. By default, it is 7 days. It can be configured between 0 and 30 days. Configure it as zero to disable alert throttling. Whenever a given executable property changes (malware confidence or classification), the alert generation interval is reset for that executable.
Note
Filter functionality is not supported for Endpoint Intelligence Agent alerts.