Investigate & Recover — Assets Tab
Introduction
The Assets tab, on the Investigate & Recover page for a Threat Detections event, shows the share permissions for the affected user across all impacted shares. Each share is listed with its path, device, and access zone.
Expanding a share shows the full ACL (Access Control List), including:
- Permission — the access level (READ, WRITE, FULL)
- Permission Type — whether the permission is ALLOW or DENY
- Trustee ID — the SID of the account the permission is applied to
- Trustee Name — the resolved account name
- Trustee Type — whether the account is a USER, GROUP, or WELLKNOWN
Using This Tab
This view is particularly useful for:
- Verifying that a lockout is correctly applied — a DENY READ entry should be visible for the affected user on every impacted share.
- Confirming a restore completed correctly — the DENY entry should be removed once user access has been restored.
- Understanding what data the user had access to before and during the event.
See also
- Recovery — Restore user access and verify the DENY permission has been removed here afterward.
- Threat Detections — Overview — Back to the Threat Detections feature page.