Hostname in investigation report
complete
Autopilot
Merged in a post:
ESPM needs to display the hostname associated with a finding
T
Todd Wentz
I just enabled ESPM in my environment and immediately saw it detect SafeDomain Guardian running on one of my endpoints.
The finding provided quite a bit of useful detail, including the full executable path, execution count, package family name, and Microsoft Store package ID. However, it did not identify which device was running the application.
In my case, I only manage a relatively small number of endpoints, so I was able to narrow it down manually. In a larger environment—or if the same application were present on multiple devices—that would quickly become much more difficult and time-consuming.
At minimum, ESPM findings should include the associated organization and hostname, or otherwise provide a way to pivot from the application/process event to the endpoint that generated it.
Since the underlying telemetry is already detailed enough to show the executable path and process activity, tying that information back to the originating device would make ESPM findings significantly more actionable.
If this has already been requested, feel free to merge this with the existing feedback.
Patrick Sofo [Security Product Manager]
updated the status to
complete
M
Mark Bestel
Hi Patrick. It works really well. Thank you.
Patrick Sofo [Security Product Manager]
Hi Mark Bestel, does the new Signals Investigated dashboard with the linked hostname meet your need? If so I will mark this complete, if not please share a bit more info.
R
Robert Ellis
Agreed. This is painful.