View and manage files identified and quarantined by Server & Workload Protection to contain malware.
An identified file is a file that the agent found to be or to contain malware, and
has been encrypted and moved to a special folder on the protected computer. To view
identified files in Server & Workload Protection, go to access the Protection Manager
and go to
.Support for viewing and restoring files depends on the Anti-Malware configuration,
and the operating system of the endpoint where the file was found:
-
On Windows agents, you can view and restore cleaned, deleted, or quarantined files.
-
On Linux agents, you can view and restore only quarantined files.
For information about events that are generated when malware is encountered, see Anti-Malware events.
From the Identified Files list, you can take several actions:
Action
|
Description
|
Details
|
||
View identified files
|
Identified Files presents a list of files Server & Workload Protection identified
|
Identified Files lists the following information:
|
||
Search for a file
|
Use the filters or advanced search to locate specific files
|
Identified Files features two basic filters:
To use the advanced search, click Search this page and select Open Advanced Search. For more information, seeSearch for an identified file.
|
||
View detailed information
|
The Details screen provides detailed information for the identified file
|
Select a file and click
![]() The Details window lists the following information:
|
||
Delete a file
|
Deleting a file permanently removes the file from the endpoint
|
Select an identified file and click
![]() |
||
Export file information
|
Export and download the detailed information of an infected file as a CSV
This exports the detailed information of the infected file, not the infected file.
|
Select an identified file and click
![]() |
||
Restore a file
|
Restore an identified file to the original location and condition
|
Select an identified file and click
![]() |
||
Download a file
|
Download an encrypted file from the infected computer
|
Select an identified file and click
![]() |
||
Add or remove columns from the list view
|
Manage which information to display on the Identified Files list
|
Click
![]() |
||
View details of the infected endpoint
|
Display the detailed information of the endpoint
|
Right-click an identified file and select
![]() |
||
View the event
|
Display the Anti-Malware event associated with the identified file
|
Right-click an identified file and select
![]() |