Worry-Free Services creates a Noteworthy Event when a threat detection correlates to one or more potentially suspicious objects. A Noteworthy Event contains information about the target endpoint, Analysis Chain, First Observed Object, and noteworthy objects.
The following table outlines the tasks available for Noteworthy Events.
Task |
Description |
---|---|
Filter the list |
Use the time period drop-down list to filter the list. |
Change the event status |
Select events from the list, click Mark As, and select one of the following statuses:
Tip:
Closed investigations are hidden by default. To show hidden investigations, disable Hide closed investigations. |
Export events |
Click Export All to save all events in a CSV file. |
View the Analysis Chain |
Click the link in the Analysis Chain column to view more details about the event and perform further investigation on noteworthy objects. For more information, see Analysis Chains. |