WithSecure Inspector Summary

Summary

PropertyValue
Production StatusPreview (Beta)
CategoryEndpoint
DiscoversCustomer company organizations under the MSP partner account

Description

Monitors WithSecure Elements endpoint protection (EPP/EDR). Parent enumerates customer company organizations under an MSP partner; each child reports that customer's protected devices, endpoint-security posture (protection status, malware/firewall/EDR module state, client and definition versions, patch posture, disk encryption), open EDR incidents, and recent security events.


Data View Information

Parent Overview Table

  • Discovered Organizations — lists each customer company organization discovered under the MSP partner account, with a Summary column set (3 columns total).

Parent Data Tab Headers

  • Organization ID
  • Organization Name
  • Organization Type

Child Overview Table

  • Overview — per-customer posture summary: device counts, protection/malware/patch/encryption rollups, open EDR incidents, and recent security events.

Child Data Tab Headers

  • Devices (14 columns) — name, type, online state, OS + version, client version, protection status, malware/firewall/device-control/application-control/DataGuard module state, EDR incident counts, patch state, disk-encryption state, IP/MAC addresses, last user, subscription, timestamps.
  • Security Posture (11 columns) — per-device security-module state, EDR incident counts, definitions version.
  • EDR Incidents (8 columns) — name, severity, risk level/score, status, resolution, timestamps. (EDR-licensed organizations only.)
  • Security Events (7 columns) — severity, engine, action, message, device, user, timestamp. (Last 7 days, critical/warning, EPP + EDR.)

Metrics

MetricDescription
WithSecure: Device CountTotal protected devices in the organization.
WithSecure: Devices OnlineDevices that communicated in the last 12 hours.
WithSecure: Devices CriticalDevices in a critical or isolated protection state.
WithSecure: Devices With Malware IssuesDevices whose malware protection is not enabled.
WithSecure: Devices Missing Critical UpdatesDevices missing critical OS updates.
WithSecure: Devices UnencryptedDevices without disk encryption enabled.
WithSecure: Open EDR IncidentsOpen EDR incidents (Broad Context Detections).
WithSecure: Recent Security EventsSecurity events in the last 7 days (critical/warning).
WithSecure: Device NamesNames of all protected devices (for new-device detection).
WithSecure: Critical DevicesNames of devices in critical/isolated protection state.

Actionable Alerts

RuleTriggerSeverity
Device Protection DegradedMore devices become critical/isolatedHigh
Malware Protection DisabledMore devices have malware protection offHigh
New Open EDR IncidentOpen EDR incident count increasesHigh
Devices Missing Critical UpdatesMore devices missing critical updatesMedium
Disk Encryption DisabledMore devices unencryptedMedium
Critical Devices ChangedThe set of critical devices changesMedium
New Device RegisteredA new device appearsLow
Devices Offline IncreasedOnline device count decreasesLow
Recent Security Events SpikeRecent event count increasesLow

Did this page help you?