When you log in to the Monarx web app you'll find different modules on the left navigation pane. Each module represents a separate page with relevant information about your servers, agents, files, etc. Some of the most useful modules are listed below.
This is default module shown after login. It is a high-level view of Monarx in your environments with some useful charts and graphs, all of which allow you to drill in to more detailed data.
Shows all the individual instances of malware files found in your environments including important details such as: Classification (malicious or compromised), Status (the remediation action taken on that file), User (domain owner), File Path, and more. You can see what each column means by mousing over the info icon (“i”) to the right of each column header. More information about each individual term will follow later.
Shows the users with the most malware files found. This module aggregates the data from the Current Malware module by user. You can drill into the underlying records for each row by clicking on the down-chevron (<icon>) next to the user name. Filters on the underlying data can be used to show the users with the most malware discovered on a particular day, with a particular filename, with particular content (SHA), etc.
Shows the servers with the most malware files found. This module aggregates the data from the Current Malware module by server. You can drill into the underlying records for each row by clicking on the down-chevron (<icon>) next to the hostname. Filters on the underlying data can be used to show the servers with the most malware discovered on a particular day, with a particular filename, with particular content (SHA), etc.
Shows the most common unique malware files found identified by the hash (SHA) of their content. This module aggregates the data from the Current Malware module by SHA. You can drill into the underlying records for each row by clicking on the down-chevron (<icon>) next to the SHA value. Filters on the underlying data can be used to show the most common unique files discovered on a particular day, with a particular filename, on a particular server, etc.
The Agents module shows all of the agents that have been installed in your enterprise, including the agent version, tags, Active Protection status, etc. You can change the Active Protection status – disabled, enabled for all users, or enabled per-user – by selecting a row and clicking on the “CONFIGURE” button in the upper right. See Insights Only and Active Protection modes for more detail.
Filter and Smart Search
Monarx has robust filtering capabilities that can be accessed on the right side in any module. You can query on any column hidden or shown by hitting “Add” then “Apply”. You can also filter by using the smart search bar at the top center of each module. Simply start to type what you’re looking for and a drop down of pre-populated common queries will appear.