LeeWei Posted October 2, 2018 ID:1272843 Share Posted October 2, 2018 Hi all, Please check out the Malwarebytes Cloud Excel Addin available. https://support.malwarebytes.com/docs/DOC-2672 Use this forum thread to ask questions, report bugs, and suggest any enhancements. Lee Wei Link to post Share on other sites More sharing options...
LeeWei Posted October 2, 2018 Author ID:1272844 Share Posted October 2, 2018 Example screen shot: Link to post Share on other sites More sharing options...
Kalrand Posted November 27, 2018 ID:1283366 Share Posted November 27, 2018 Great add-in, really wish these types of reports were available through the cloud. One small issue, the times are a bit off. Currently it is 9:49AM on 11/27, but I'm seeing times in the Last Seen column as 2:44PM on 11/27. Time zone, as displayed, is set to Eastern Standard Time UTC-5:00. Add-in version is 1.7.6. Link to post Share on other sites More sharing options...
LeeWei Posted November 27, 2018 Author ID:1283399 Share Posted November 27, 2018 @Kalrand, thanks for the feedback. Yes all the datetimes are currently shown in UTC. I have already changed the default to show local time in the next version that I have yet to release (v2.0). It will show the datetimes in local timezone, but you can change to UTC if needed. Any other comments, bugs, or enhancements are welcome! Lee Wei Link to post Share on other sites More sharing options...
Kalrand Posted November 27, 2018 ID:1283401 Share Posted November 27, 2018 @LeeWei Thank you! Link to post Share on other sites More sharing options...
Kernel009 Posted November 27, 2018 ID:1283411 Share Posted November 27, 2018 Any idea why I'm getting this error? Link to post Share on other sites More sharing options...
LeeWei Posted November 27, 2018 Author ID:1283428 Share Posted November 27, 2018 @Kernel009 the error technically means that the Cloud server cannot service our API request. The API service returns errors in JSON. The HTTP/HTML error indicates that the API service is not reached. So it could be network, the API service, etc. Behind the scene, when we retrieve the "Agent Info", it does invoke as many APIs as you have endpoints identified. It is a looping call. Is it happening for the same computer name? Is this happening consistently, or sporadic? If this happens a lot, I can manage the error better to provide better experience. Link to post Share on other sites More sharing options...
Kernel009 Posted December 3, 2018 ID:1284570 Share Posted December 3, 2018 Actually, it cleared up so I suspect it was some sort of congestion. Thanks for the info! Link to post Share on other sites More sharing options...
syarbrough Posted December 11, 2018 ID:1286462 Share Posted December 11, 2018 Hi Lee Wei, Great addin, I have been looking for this type of reporting and it works very well. I am trying to filter down to a group and run a summary report for my end users, however it is pulling data from all devices in all groups from Detections and Threats and including this in the Summary report. It will show endpoints from other groups. Is there a way to import only Detections and Threats for one group? Thanks Link to post Share on other sites More sharing options...
LeeWei Posted December 11, 2018 Author ID:1286480 Share Posted December 11, 2018 1 hour ago, syarbrough said: Hi Lee Wei, Great addin, I have been looking for this type of reporting and it works very well. I am trying to filter down to a group and run a summary report for my end users, however it is pulling data from all devices in all groups from Detections and Threats and including this in the Summary report. It will show endpoints from other groups. Is there a way to import only Detections and Threats for one group? Thanks @syarbrough I understand and love the idea. I do lament that the detection data does not reconcile with endpoint selection. On my list of enhancements now, thank you! Link to post Share on other sites More sharing options...
LeeWei Posted December 20, 2018 Author ID:1288209 Share Posted December 20, 2018 If you use the Excel Addin, please consider upgrading to v2.0 that I have just published. https://support.malwarebytes.com/docs/DOC-2672 Other than bug fixes, I have incorporated a lot of features and requests from you guys. One main enhancement is the management of Endpoint Statuses now available in the Cloud console. You can see summary charts of endpoints with the different statuses like Scan Needed, Remediation Required, Reboot Required, etc. A summary report with these data points are included as the primary KPI. And lastly, there is a "Take Status Action" dialog to take the actions in bulk. Also added is a better way of handling and managing groups. You can filter endpoints by a group hierarchy. Per usual, I appreciate bug reports and enhancement requests. Link to post Share on other sites More sharing options...
RickyF Posted January 30, 2019 ID:1295539 Share Posted January 30, 2019 Hi LeeWei, I love the Addin. Congratulations for the great job you made. I have a question. My customers are all different people (mostly private, I mean non corporations) who bought just one licence. I take care that theirs computers are nice and clean. I need to send them by email every week an status report about all the detection or events that they might have had on the past week. Do you know how can I achieve this with your addin? Just one report from just one endpoint to send to just one email. Of course once I had the solution for one device I will have to do the same for all the devices so some kind of macro I guess will also be needed to send the emails on batch process in the long run but I can start to send them manually. Complicated? Regards Ricky Link to post Share on other sites More sharing options...
LeeWei Posted January 30, 2019 Author ID:1295688 Share Posted January 30, 2019 On 12/11/2018 at 2:44 PM, syarbrough said: Hi Lee Wei, Great addin, I have been looking for this type of reporting and it works very well. I am trying to filter down to a group and run a summary report for my end users, however it is pulling data from all devices in all groups from Detections and Threats and including this in the Summary report. It will show endpoints from other groups. Is there a way to import only Detections and Threats for one group? Thanks @syarbrough, I forgot to follow-up with you. The new version 2.2 will now report threats and detections only for the endpoints (e.g. group) that you have selected. Thank you for the suggestion and input. Link to post Share on other sites More sharing options...
LeeWei Posted January 30, 2019 Author ID:1295691 Share Posted January 30, 2019 7 hours ago, RickyF said: Hi LeeWei, I love the Addin. Congratulations for the great job you made. I have a question. My customers are all different people (mostly private, I mean non corporations) who bought just one licence. I take care that theirs computers are nice and clean. I need to send them by email every week an status report about all the detection or events that they might have had on the past week. Do you know how can I achieve this with your addin? Just one report from just one endpoint to send to just one email. Of course once I had the solution for one device I will have to do the same for all the devices so some kind of macro I guess will also be needed to send the emails on batch process in the long run but I can start to send them manually. Complicated? Regards Ricky @RickyF, hah, I have not targeted (designed...) the reports to highlight one single endpoint, they are most meant for a group of computers. This is why we see Top 10 categories etc. I think the report will be very different, and you can provide all the details of the endpoint including OS details, network, software installed, Windows updates. Basically everything that is available when drilling into a single endpoint. Past that, many have asked for the ability to schedule the reports for delivery. Yes both these will require some work, but I appreciate the feedback. Link to post Share on other sites More sharing options...
RickyF Posted January 31, 2019 ID:1295835 Share Posted January 31, 2019 16 hours ago, LeeWei said: @RickyF, hah, I have not targeted (designed...) the reports to highlight one single endpoint, they are most meant for a group of computers. This is why we see Top 10 categories etc. I think the report will be very different, and you can provide all the details of the endpoint including OS details, network, software installed, Windows updates. Basically everything that is available when drilling into a single endpoint. Past that, many have asked for the ability to schedule the reports for delivery. Yes both these will require some work, but I appreciate the feedback. Hi @LeeWei, Thanks for your reply. A simple "detection and threats" report for one single endpoint would be sufficient. What do you recommend in order to do that? I mean what would you do if you where on my shoes knowing that is vital for your business? Maybe you know somebody that can do this job for me.... Thanks again. Ricky Link to post Share on other sites More sharing options...
LeeWei Posted January 31, 2019 Author ID:1295966 Share Posted January 31, 2019 9 hours ago, RickyF said: Hi @LeeWei, Thanks for your reply. A simple "detection and threats" report for one single endpoint would be sufficient. What do you recommend in order to do that? I mean what would you do if you where on my shoes knowing that is vital for your business? Maybe you know somebody that can do this job for me.... Thanks again. Ricky @RickyF if you want just the detection data for one endpoint, you can do the following. - In the "Endpoint Computers" export button, use the search field to find your endpoint. - Following that, any data extracted from the "Detections and Threats" button will be filter for this endpoint only. This way, any charts and summary will also be for this endpoint. Link to post Share on other sites More sharing options...
LeeWei Posted January 31, 2019 Author ID:1295967 Share Posted January 31, 2019 A few people have asked for the Excel Addin to support Excel 2010. I have just added that in the new version v2.3. Link to post Share on other sites More sharing options...
RickyF Posted February 4, 2019 ID:1296638 Share Posted February 4, 2019 On 1/31/2019 at 10:36 PM, LeeWei said: @RickyF if you want just the detection data for one endpoint, you can do the following. - In the "Endpoint Computers" export button, use the search field to find your endpoint. - Following that, any data extracted from the "Detections and Threats" button will be filter for this endpoint only. This way, any charts and summary will also be for this endpoint. hI @LeeWei, I just tried to do what you told me and I have no data. Let me explain. For example in the screen shot from the cloud I enclose here there is one mac with 25 detection. When I try to see this detection with the addin there is no data. What I am do in wrong? Thanks ricky Link to post Share on other sites More sharing options...
LeeWei Posted February 4, 2019 Author ID:1296645 Share Posted February 4, 2019 @RickyF, search for the machine name in the "Endpoint Computers" button, NOT "Detection and Threats". Link to post Share on other sites More sharing options...
RickyF Posted February 5, 2019 ID:1296819 Share Posted February 5, 2019 @leewei, thanks for the help. now I got it right! sorry for my obtuseness. 🙂 Link to post Share on other sites More sharing options...
RickyF Posted February 5, 2019 ID:1296820 Share Posted February 5, 2019 by the way @LeeWeiwhen you have a version that can filter by endpoint let me know!! thanks again Ricky Link to post Share on other sites More sharing options...
wpclau Posted February 12, 2019 ID:1298334 Share Posted February 12, 2019 This is a really super plugin. Thank you so much for making it! I was wondering if there was a way to modify it so that I can see the last scan - it is in the api call - but it isn't available alone but as criteria in a separate query. I'm trying to make sure the policies are applying and the machines are scanning as scheduled so having "last_scanned_at": , returned would be phenomenal. Link to post Share on other sites More sharing options...
LeeWei Posted February 12, 2019 Author ID:1298338 Share Posted February 12, 2019 13 minutes ago, wpclau said: This is a really super plugin. Thank you so much for making it! I was wondering if there was a way to modify it so that I can see the last scan - it is in the api call - but it isn't available alone but as criteria in a separate query. I'm trying to make sure the policies are applying and the machines are scanning as scheduled so having "last_scanned_at": , returned would be phenomenal. @wpclau, this should have already been available under importing of Endpoint Data per the screen shot below. Let me know if you are referring to something different. Link to post Share on other sites More sharing options...
wpclau Posted February 12, 2019 ID:1298341 Share Posted February 12, 2019 Hmm...I don't see that column. Maybe I have an older version? I'll double check. Link to post Share on other sites More sharing options...
wpclau Posted February 12, 2019 ID:1298343 Share Posted February 12, 2019 Using 2.3.0 Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now