Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

Investigate & Recover — Assets Tab

Introduction

The Assets tab, on the Investigate & Recover page for a Threat Detections event, shows the share permissions for the affected user across all impacted shares. Each share is listed with its path, device, and access zone.

Expanding a share shows the full ACL (Access Control List), including:

  • Permission — the access level (READ, WRITE, FULL)
  • Permission Type — whether the permission is ALLOW or DENY
  • Trustee ID — the SID of the account the permission is applied to
  • Trustee Name — the resolved account name
  • Trustee Type — whether the account is a USER, GROUP, or WELLKNOWN

Using This Tab

This view is particularly useful for:

  • Verifying that a lockout is correctly applied — a DENY READ entry should be visible for the affected user on every impacted share.
  • Confirming a restore completed correctly — the DENY entry should be removed once user access has been restored.
  • Understanding what data the user had access to before and during the event.

See also