Skip to main content

Managing recommendations

PHASR provides actionable recommendations based on observed behavior. A standard behavioral profile associates a user with a device. When PHASR for AI Agents is enabled, an AI-agent behavioral profile includes the device name, username, and AI agent name. A recommendation can contain multiple standard and AI-agent behavioral profiles.

PHASR can generate Restrict access recommendations for behavioral profiles that are not actively using tools from the monitored categories. If the user's behavior changes, PHASR adapts by generating Allow access recommendations.

PHASR can generate Restrict access, Allow access, and Request access recommendations for AI agents. These recommendations can use existing attack vectors or attack vectors created specifically for AI-agent activity.

PHASR bases its recommendations on attack vectors related to activity types such as Tampering tools, Living off the Land Binaries, Crypto miners, Piracy tools, and Remote admin tools.

When you apply an Allow access or Restrict access recommendation, the access-editing flow lets you review the recommendation details, choose whether to restrict access, and apply the decision to departments, users, or individual behavioral profiles. The flow also displays the current restriction status and a summary of the changes before you apply them.

You can find a list of all PHASR recommendations on the PHASR recommendations page.

PHASR_recommendations_page_smart_views_981499_en.png
  1. The View options menu provides the following options for working with smart views:

    • Save - Saves the current smart view with your latest changes.

    • Save as - Creates a new smart view based on the current one.

    • Discard changes - Reverts all unsaved edits to the last saved version.

    • Add to favorites - Adds a saved smart view to your favorites.

    • Show or hide filters - Hides or displays the filters menu.

    • Open settings - Displays the Settings panel.

      You can use this panel to customize which columns are displayed in the view and enable or disable the Compact view.

  2. The Smart views section lets you customize the recommendations page. You can create your own views or use predefined ones and quickly switch between them as needed.

  3. The Filters section lets you customize which recommendations are displayed in the grid below.

    The following filters are available:

    Filtering option

    Details

    Company 

    Use the searchable drop-down menu to filter recommendations by company name.

    Only recommendations belonging to the selected company are displayed. This filter is available only to Partner companies.

    Name 

    Use the searchable drop-down menu to filter recommendations by name.

    Only selected recommendations are displayed.

    Created on 

    Use the calendar to select two dates.

    Only recommendations created between the selected dates are displayed.

    Behavioral profile identities 

    Use the searchable drop-down menu to filter recommendations by the name of the identity for which they were generated.

    Only recommendations generated for the selected identities are displayed.

    Behavioral profile resources 

    Use the searchable drop-down menu to filter recommendations by the name of the resource for which they were generated.

    Only recommendations generated for the selected resources are displayed.

    Targeted activity type 

    Use the drop-down menu to filter recommendations by the targeted activity type.

    Only recommendations targeting the selected activity types are displayed.

    Action taken 

    Use the drop-down menu to filter recommendations by their action status.

    Only recommendations with the selected action statuses are displayed.

    Recommendation type 

    Use the drop-down menu to filter recommendations by type.

  4. The Recommendations grid displays recommendations generated through PHASR behavioral analysis.

    The information available for each recommendation is displayed in the following columns:

    • Name - The name of the recommendation.

    • Attack surface reduction - Indicates the impact that applying the recommendation would have on the total attack surface.

    • Recommendation type - The type of recommendation generated based on PHASR analysis.

      • Allow access - PHASR recommends allowing access to the affected tool for the behavioral profiles included in the recommendation.

      • Restrict access - PHASR recommends restricting access to the affected tool for the behavioral profiles included in the recommendation.

      • Allow access request - A request for access to a tool that is currently restricted. You can review the request and decide whether to grant access.

    • Created on - The date and time when the recommendation was created.

    • Description - A description of the recommendation.

    • Targeted activity type - The type of activity targeted by the recommendation.

      Possible values:

      • Tampering tools

      • Living off the Land Binaries

      • Crypto miners

      • Remote admin tools

      • Piracy tools

    • Vector - The attack vector used to generate the recommendation. This column can be hidden.

    • Behavioral profiles - The total number of behavioral profiles included in the recommendation. The column displays a maximum of 9999 items, with the exact count displayed when you hover over the icon.

      Clicking the behavioral profiles icon in the grid opens the Behavioral profiles side panel, which lists the profiles for which the recommendation was generated.

    • Action taken - The status of the action taken on the recommendation.

      Possible values:

      • Action needed - The default status for recommendations generated by PHASR. Review the recommendation and take action.

      • Applied - The recommendation has been applied to all behavioral profiles for which it was generated.

      • Partially applied - The recommendation has been applied only to a subset of its behavioral profiles.

      The status changes from Action needed to Applied when the recommendation is applied to all its behavioral profiles, or to Partially applied when it is applied only to a subset.

    • Company - The company for which the recommendation was generated.

  5. The Actions menu provides actions based on the recommendation type. For Allow access and Restrict access recommendations, select the corresponding action to open the access-editing flow:

    • Restrict access - Opens the access-editing flow with Restrict selected as the default decision. Review the recommendation details, configure the affected behavioral profiles, and confirm the changes before applying them.

    • Allow access - Opens the access-editing flow with Do not restrict selected as the default decision. Review the recommendation details, configure the affected behavioral profiles, and confirm the changes before applying them.

    For Allow access request recommendations, follow the procedure in Requesting access to a tool.

    Note

    PHASR issues recommendations as it completes the learning phase for different behavioral profiles. The same recommendation may be generated multiple times, but only if the previous one has a status of Applied or Partially applied, because the initial learning phase is completed at different times on different endpoints.

    If the recommendation has the Action needed status, it is updated with more behavioral profiles as the learning phase completes.

Using the smart views

Smart views let administrators customize how recommendations are displayed. A smart view saves the current configuration of filters, columns, and layout preferences, allowing quick switching between different contexts (for example, by company, recommendation type, or activity type).

Smart views can be:

  • Predefined - Standard views available by default.

  • Custom - User-created configurations saved for later reuse.

Changes made to a smart view can be saved to update the existing one (except predefined views) or saved as a new custom view.

Allowing access based on a received recommendation

PHASR may generate an Allow access recommendation when it detects that the behavior of a user whose access was previously restricted has changed. Use the access-editing flow to review the recommendation and decide where access should be allowed.

Changes made through this flow apply only to the behavioral profiles included in the recommendation.

To apply an Allow access recommendation:

  1. In the GravityZone console, go to the PHASR recommendations page.

  2. Locate the Allow access recommendation you want to apply and do one of the following:

    • Select the recommendation name, and then select Allow access in the Recommendation details side panel.

    • Open the actions menu for the recommendation and select Allow access.

  3. In the Details step, review the following information:

    • Attack vector.

    • Targeted activity type.

    • Vector triggers.

    • Attack surface reduction.

    • MITRE tactics, techniques, or sub-techniques to which the attack vector is mapped.

    • Attack vector description.

  4. Select Next.

  5. In the Finalize step, review the affected behavioral profiles and configure the access decision.

    Behavioral profiles is selected as the default target type. Do not restrict is selected as the default decision for an Allow access recommendation.

    PHASR_allow_access_recommendation_981499_en.png
  6. Optional: Under Target type, select how to organize and apply the decision:

    • Departments - Displays the departments associated with the behavioral profiles included in the recommendation.

    • Users - Displays the users associated with the behavioral profiles included in the recommendation.

    • Behavioral profiles - Displays the individual behavioral profiles included in the recommendation. These can include standard and AI-agent behavioral profiles.

    Note

    Selecting a department or user does not extend the change to behavioral profiles that are not included in the recommendation.

  7. Use the available filters to find the departments, users, or behavioral profiles you want to manage.

  8. Review the Restriction status of each item. Depending on the selected target type, the status can be Restricted, Unrestricted, or Custom.

  9. Apply one of the following decisions:

    • Restrict - Restricts access. PHASR continues monitoring and learning.

    • Do not restrict - Allows access even if Autopilot previously determined otherwise. PHASR continues monitoring and learning.

    You can apply a decision to individual rows or use Apply to all. When you filter the grid, this control changes to Apply to filtered and applies the decision only to the filtered results.

  10. Optional: Use the inline revert control to undo a change for an individual item, or select Revert changes to restore the recommendation's initial decisions.

  11. Select Save.

  12. In the Apply changes? dialog, review:

    • The number of behavioral profiles that will be restricted.

    • The number of behavioral profiles that will be unrestricted.

    • The number of behavioral profiles that will remain unchanged.

    • The number of departments and users affected by the changes.

  13. Select Apply.

GravityZone applies all saved changes, including changes made before or after filtering the grid, and displays a notification indicating whether the operation was successful. The recommendation status changes to Applied or Partially applied, depending on whether the recommendation was applied to all or only some of its behavioral profiles.

Restricting access based on a received recommendation

PHASR generates a Restrict access recommendation when it determines that behavioral profiles do not require access to a monitored tool. Use the access-editing flow to review the recommendation and decide where access should be restricted.

Changes made through this flow apply only to the behavioral profiles included in the recommendation.

To apply a Restrict access recommendation:

  1. In the GravityZone console, go to the PHASR recommendations page.

  2. Locate the Restrict access recommendation you want to apply and do one of the following:

    • Select the recommendation name, and then select Restrict access in the Recommendation details side panel.

    • Open the actions menu for the recommendation and select Restrict access.

  3. In the Details step, review the following information:

    • Attack vector.

    • Targeted activity type.

    • Vector triggers.

    • Attack surface reduction.

    • MITRE tactics, techniques, or sub-techniques to which the attack vector is mapped.

    • Attack vector description.

  4. Select Next.

  5. In the Finalize step, review the affected behavioral profiles and configure the access decision.

    Behavioral profiles is selected as the default target type. Restrict is selected as the default decision for a Restrict access recommendation.

    PHASR_remove_access_recommendation_981499_en.png
  6. Optional: Under Target type, select how to organize and apply the decision:

    • Departments - Displays the departments associated with the behavioral profiles included in the recommendation.

    • Users - Displays the users associated with the behavioral profiles included in the recommendation.

    • Behavioral profiles - Displays the individual behavioral profiles included in the recommendation. These can include standard and AI-agent behavioral profiles.

    Note

    Selecting a department or user does not extend the change to behavioral profiles that are not included in the recommendation.

  7. Use the available filters to find the departments, users, or behavioral profiles you want to manage.

  8. Review the Restriction status of each item. Depending on the selected target type, the status can be Restricted, Unrestricted, or Custom.

  9. Apply one of the following decisions:

    • Restrict - Restricts access. PHASR continues monitoring and learning.

    • Do not restrict - Allows access even if Autopilot previously determined otherwise. PHASR continues monitoring and learning.

    You can apply a decision to individual rows or use Apply to all. When you filter the grid, this control changes to Apply to filtered and applies the decision only to the filtered results.

  10. Optional: Use the inline revert control to undo a change for an individual item, or select Revert changes to restore the recommendation's initial decisions.

  11. Select Save.

  12. In the Apply changes? dialog, review:

    • The number of behavioral profiles that will be restricted.

    • The number of behavioral profiles that will be unrestricted.

    • The number of behavioral profiles that will remain unchanged.

    • The number of departments and users affected by the changes.

  13. Select Apply.

GravityZone applies all saved changes, including changes made before or after filtering the grid, and displays a notification indicating whether the operation was successful. The recommendation status changes to Applied or Partially applied, depending on whether the recommendation was applied to all or only some of its behavioral profiles.

You can see which applications PHASR is restricting on a specific endpoint in the BEST interface.

Requesting access to a tool

When PHASR blocks a tool, behavioral profiles can request access directly from the BEST interface, whether the restriction was applied automatically (Autopilot) or manually (Direct control). When PHASR for AI Agents is enabled, an access request can also be generated for a blocked AI agent. The resulting recommendation identifies the affected device, username, and AI agent.

Note

For Windows and macOS users to receive Request access alert pop-ups, the Display alert pop-ups option must be enabled in the applied policy under General > Agent > Notifications.

PHASR_policy_agent_alerts_popups.png

The option to request access is available only if the Request access setting is enabled in the applied security policy under Risk Management > PHASR   for the corresponding PHASR category.

PHASR_policy.png
In GravityZone Control Center 
  1. On the PHASR recommendations page, open the Requested access smart view to display the requests received. Alternatively, use the Recommendation type filter and select Allow access request.

    GZ_PHASR_recommendations_request_access.png
  2. Click the recommendation name to view the request details, including the business justification and available actions.

    GZ_PHASR_recommendations_request_access_side_panel.png
  3. Select one of the following actions:

    • Allow access - Grants access to the requested tool for the selected behavioral profiles.

    • Deny access - Denies the request and maintains the restriction for the selected behavioral profiles.

    Note

    Request access actions are recorded in User Activity. To view them, filter the entries by the corresponding action in the PHASR recommendations area (such as Request access granted or Request access denied).

    After an action is applied, the Action taken field for the recommendation updates to Applied.

    If you allow access:

    • The behavioral profile has a five-day window to use the tool.

    • If the tool is not used within those five days, it is blocked again.

    • If the behavioral profile uses the tool, access remains active as long as usage continues.

    • PHASR blocks the tool again only if the behavioral profile stops using it and the PHASR learning period has passed, which takes a minimum of 30 days and can extend up to 60 days depending on the attack vector.

For the actions to perform on the endpoint, see the instructions for your operating system:

Viewing recommendation details

You can view additional information about a recommendation in the Recommendation details side panel. To open the side panel, click the recommendation name in the Name column.

PHASR_recommendations_sidebar_981499_en.png
  • General - Contains the following information:

    • Target activity type - The type of activity targeted by the recommendation.

    • Attack surface reduction - Indicates the impact that applying the recommendation would have on the total attack surface.

    • Created on - The date and time when the recommendation was created.

    • Vector - The attack vector used to generate the recommendation.

      Note

      The vector name is a link that opens the PHASR Attack Vectors grid in a new tab, filtered by the selected vector.

    • Behavioral profiles - The total number of behavioral profiles included in the recommendation.

    • Action taken - The status of the action taken on the recommendation.

  • Details - Describes the risk addressed by the recommendation.

  • Recommendation mitigation - The action suggested to address the risk.

  • Allow access or Restrict access - Opens the two-step access-editing flow for the recommendation. The available action depends on the recommendation type.