Product Update Bulletin 19.3

  • 4 November 2014
  • 3 replies
  • 31 views

Userlevel 7
Badge +35
  • Retired Webrooter
  • 831 replies
 


Release 19.3 introduces Webroot Endpoint Forensics – File Intelligence Views. These let Administrators’ quickly get relevant information on any threat or unknown files within their network and compliments the release of the ‘dwell time’ reporting we introduced in our last release.  This new feature is also part of our longer term plan to provide more context to  Administrators’ on the threat landscape within their endpoint environment.
 
NEW – Endpoint Forensics - File Intelligence Views – Administrators need to understand the risks posed by threats and ‘undetermined’ file types. Our endpoint forensics file intelligence views provide that insight quickly and easily for any filename.
 
  1. NEW – Endpoint Forensics - File Intelligence Views – Administrators can access these views by clicking on any filename in the console. They will then see:a. Agent, Rule and Cloud determination information (when hovering the mouse cursor over a determination).
    b. Integrated Webroot Intelligence Network (WIN) data providing information on the first time that a file has been first seen (FS) by WIN and its Global ‘popularity’ (how much it has been seen by others).
    c. Product/Vendor links to Google - to allow the Admininstrator to get a wider context on the file – useful for occasions when they are unsure on the classification.
    d. Ability to override the file, for white or blacklisting purposes.
    e. Console popularity – how many times it has been seen within the console deployment and when.
    f. Endpoint Dwell time – how long the file has been seen on the device in question.


An example of a single threat seen twice with a ‘0s’ zero seconds (instantly remediated) Dwell Time
For further information on  ‘Dwell Time’ please visit the help link at:
http://live.webrootanywhere.com/content/1330/About-Dwell-Time

3 replies

Userlevel 6
Sounds like a great addition and a step towards my feature request :)

https://community.webroot.com/t5/Feature-Requests/More-useful-information-on-undetermined-software/idi-p/165699
 
By the way; what's 'agent determination'? I do understand that a file can either be determined as bad by the cloud or a rule; but how can the agent make a determination?
This is a really neat feature!  However, I would prefer to see some of the outstanding bugs fixed before new features are added:
https://community.webroot.com/t5/Feature-Requests/Out-of-Sorts/idc-p/162863
 
And we still cannot see the full path to the malware:
https://community.webroot.com/t5/Feature-Requests/Show-the-actual-path-of-a-virus/idi-p/53990
 
And how can we access the white/blacklisting ability from this new dialoge?  (1.d)
 
Userlevel 7
Badge +35
@ wrote:
Sounds like a great addition and a step towards my feature request :)

https://community.webroot.com/t5/Feature-Requests/More-useful-information-on-undetermined-software/idi-p/165699
 
By the way; what's 'agent determination'? I do understand that a file can either be determined as bad by the cloud or a rule; but how can the agent make a determination?
Agent Determination is when an unknown file has been determined as bad by the agent based on heuristic behavior. Not as common but definitely can happen especially with new variants of previously known malware.

Reply