View and manage files identified and quarantined by Server & Workload Protection to contain malware.
An identified file is a file that the agent found to be or to contain malware, and
has been encrypted and moved to a special folder on the protected computer. To view
identified files in Server & Workload Protection, go to access the Protection Manager
and go to .
Support for viewing and restoring files depends on the Anti-Malware configuration,
and the operating system of the endpoint where the file was found:
-
On Windows agents, you can view and restore cleaned, deleted, or quarantined files.
-
On Linux agents, you can view and restore only quarantined files.
For information about events that are generated when malware is encountered, see Anti-Malware events.
From the Identified Files list, you can take several actions:
|
Action
|
Description
|
Details
|
||
|
View identified files
|
Identified Files presents a list of files Server & Workload Protection identified
|
Identified Files lists the following information:
|
||
|
Search for a file
|
Use the filters or advanced search to locate specific files
|
Identified Files features two basic filters:
To use the advanced search, click Search this page and select Open Advanced Search. For more information, seeSearch for an identified file.
|
||
|
View detailed information
|
The Details screen provides detailed information for the identified file
|
Select a file and click
The Details window lists the following information:
|
||
|
Delete a file
|
Deleting a file permanently removes the file from the endpoint
|
Select an identified file and click
|
||
|
Export file information
|
Export and download the detailed information of an infected file as a CSV
This exports the detailed information of the infected file, not the infected file.
|
Select an identified file and click
|
||
|
Restore a file
|
Restore an identified file to the original location and condition
|
Select an identified file and click
|
||
|
Download a file
|
Download an encrypted file from the infected computer
|
Select an identified file and click
|
||
|
Add or remove columns from the list view
|
Manage which information to display on the Identified Files list
|
Click
|
||
|
View details of the infected endpoint
|
Display the detailed information of the endpoint
|
Right-click an identified file and select
|
||
|
View the event
|
Display the Anti-Malware event associated with the identified file
|
Right-click an identified file and select
|
