Views:
The Detection & ResponseNoteworthy Events / DetectionAnalysis Chain for {Customer} screen provides details about a Noteworthy Event and allows you to perform further investigation on Noteworthy Objects. You can isolate or run an Aggressive Scan on the affected endpoint.
  • Use the Status drop-down list to change the event status.
  • Click Actions Taken to view a list of actions taken upon the event.
  • Click export.png and select Analysis Chain to export the Analysis Chain to a ZIP file.
The following table describes the sections of the Detection & ResponseNoteworthy Events / DetectionAnalysis Chain for {Customer} screen:
Information
Description
Indicator of Attack
Provides an overview of the Noteworthy Event. The following information may be included:
  • The security threat that triggered the creation of the Noteworthy Event
    Note
    Note
    The security threat in a Noteworthy Event is automatically blocked by Trend Micro. Focus on Noteworthy Objects correlated with the security threat.
  • The Noteworthy Object(s) correlated with the security threat
  • The potential damage to your customer's environment if the Noteworthy Object is malicious
Recommended Actions
Lists possible actions you can take to mitigate the threat to your customer's environment if the Noteworthy Object is malicious.
Endpoint
Displays details about the endpoint that was investigated
  • Click the endpoint name and user name to view details.
  • Click caret-down.jpg and select Isolate Endpoint to disconnect the endpoint from the network. During isolation, the Security Agent can only communicate with the server.
  • Click caret-down.jpg and select Start Aggressive Scan to fix unresolved security risks.
    Note
    Note
    You can perform Aggressive Scan on isolated endpoints.
    Aggressive Scan is not currently supported for Mac endpoints.
First Observed Object
Appears as the first object in the Analysis Chain, suspected of introducing the security threat to the target endpoint.
Note
Note
This is often the entry point of a targeted attack.
  • Hover over an object and click search.png to locate the object in the Analysis Chain.
Security Threat
The detected threat that Worry-Free Services uses to create the Noteworthy Event.
  • Hover over an object and click search.png to locate the object in the Analysis Chain.
Noteworthy Objects
Highlights objects in the chain that are possibly malicious, based on existing Trend Micro intelligence
The value counts the number of unique noteworthy objects in the chain.
  • Click to view the list of noteworthy objects.
  • Hover over an object and click search.png to locate the object in the Analysis Chain.
Analysis Chain
Displays a visual analysis of the objects involved in an event
  • Hover over legend-icon.png to learn more about Analysis Chain icons.
    For more information, see Analysis Chain icons.
Details Panel
Provides further information about selected objects.
  • Click any object in the Analysis Chain to view its details panel.
  • For more information, see Details panels.