Select the core attribute as Executable Hash and click the hyperlink to view the following details:
Field | Description |
|---|---|
View Detections | Takes you to the Malware Files page to view the malware confidence computed by individual engines and the overall malware confidence for the executable |
Hash | Displays the file hash. This link takes you to the Threat Explorer with a filter on the hash and the selected time. |
Binary Name (type) | Displays the binary name and the type, whether process or library |
Product Name | Displays the product name for the executable |
Version | Displays the product version number |
Malware Confidence | Displays the malware confidence level returned by the configured EIA. The malware confidence values are very high, high, medium, low, very low, and unknown. |
Classification | Displays the executable classification whether blocked, allowed, or unclassified |
Classified | Displays the method of classification and the timestamp, only for classified executables |
Certificate Status | Displays if the certificate is from a trusted CA or not. Valid values for executables are Signed and Signed and Trusted. If the executables are unsigned, the status displays blank. |
Certificate Signer | Displays the certificate signer name. |
GTI Reputation | Displays the file reputation received from GTI. Valid values are Very Low, Low, Medium, High, Very High, and Unknown. |
Malware Indicators | Shows some of the methods that were used to compute the executable reputation. |
Invoked Libraries | Lists all libraries (DLLs) invoked by the executable. The DLLs are displayed only if EIA finds the corresponding malware confidence to be greater than or equal to the ePO - On-prem Reputation Threshold value. By default, the ePO - On-prem Reputation Threshold value is Medium.
|
Name | Displays names of the library files invoked by the executable |
Hash | Displays the file hash. This link takes you to the Threat Explorer with a filter on the hash and the selected time. |
Malware Confidence | Displays the malware confidence level returned by the configured EIA |
Select
to navigate to Attack Log and view the alerts that matches the selected endpoint executable.
Important
All the other top N security tables are populated with the data related to the selected core attribute and admin domain.
At any time, you can click
to leave the selected core attribute and return to the main Threat Explorer page.