New features in 8.6.0
The following are the new features available with the Xprotect version 8.6.0 released on the 10th of July, 2020:
Enhancement on the Hosts page
Use the Two new filters, Queued Policy and Policy Publish Status to filter hosts on the Hosts page.
-
Queued Policy filters hosts on which the selected Policy is still queued (scheduled).
- Policy Publish Status filters hosts by the status of the policy push on them, by one of the following - Scheduled (queued), In Progress, Successful and Failed.
Enhancement on the Policies page
On the policy's floating panel, click the links in the Status Details section to get to a filtered view of the Hosts page by the status of the policy push to the hosts. Hosts are filtered by one of the following - Scheduled (queued), In Progress, Successful and Failed.
See the entire process tree for the process that resulted in an alert
-
On the alert's floating panel, click Show Process Tree to see the process tree in a tabular format. The child processes are listed in the first column and it's parent processes in the second column. By design, the processes listed in this table are always sorted by the root process at the top. Other columns in this table include PID, PPID, Trust Score of the child process, number of network connections made by the process, and the user or internal process that used the process.
-
Open a process' floating panel to see the path, MD5, commands executed, and the status of both the child and parent processes.
-
Click on the Trust Score link in the Trust column of a process to see the Virus Total's assessment page for the process.
-
Search for specific processes or sort the processes by their reversed (descending) order/sequence of the Process IDs.
-
Click Fetch Process Tree from Host (located at the top-right corner of the table) to fetch the latest process tree from the agent installed on the host.