> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Understanding the Detections Page

> Navigate the Iru Endpoint Detections page. Review dashboard widgets, filters, the detections table, threat detail views, and device record detections.

<Callout icon="list-check" color="#71118C" iconType="regular">This guide applies to Mac computers and Windows devices</Callout>

### About the Detections Page

The **Detections** page in the Iru Endpoint Web App is where admins review threat events, monitor trends, and take response actions for devices with the EDR Library Item assigned. Access it by clicking **Detections** in the left-hand navigation bar (under **Endpoint**).

For an overview of EDR capabilities and posture modes, see [Endpoint Detection & Response (EDR) Overview](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview).

### Dashboard Widgets

#### Detections Over Time

The **Detections Over Time** graph displays a chronological overview of security threats detected within a specified timeframe. By default, the graph shows data for the past 30 days. At the top of the **Detections** tab, click the date range beside **Viewing** (default **Last 30 days**) to change the period, such as **Last 24 hours** through **Last 90 days**, **All time**, or **Custom date range**.

<Note>
  If you choose a date range exceeding 90 days, the system automatically limits the display to 90 days.
</Note>

The graph offers three visualization options:

* **Granular** — Shows every individual threat detection
* **Smooth** — Displays general trends and patterns
* **Balanced** — Default setting between detailed data and trend visualization

<Frame>
  <img src="https://mintcdn.com/iru/vtXsax0ggvTiXavA/assets/media/images/iru-edr-detections-over-time.png?fit=max&auto=format&n=vtXsax0ggvTiXavA&q=85&s=ddc8faace736df0f9144a82bb065caaf" alt="Detections Over Time graph on the Detections page" width="4000" height="762" data-path="assets/media/images/iru-edr-detections-over-time.png" />
</Frame>

#### Detections By Severity

The **Detections By Severity** view provides a visual breakdown of detections by severity level. Each detection is assigned one of five severity levels: Critical, High, Medium, Low, and Informational.

<Frame>
  <img src="https://mintcdn.com/iru/vtXsax0ggvTiXavA/assets/media/images/iru-edr-detections-by-severity.png?fit=max&auto=format&n=vtXsax0ggvTiXavA&q=85&s=8cc7c5b8c750e6a494295cf970a21ed6" alt="Iru Endpoint Detections page dashboard with Detections over time graph, Detections by severity donut chart and severity legend, and Devices under threat count" width="4000" height="774" data-path="assets/media/images/iru-edr-detections-by-severity.png" />
</Frame>

#### Devices Under Threat

The **Devices Under Threat** metric shows how many devices currently have active security threats. Adjust the timeframe using the date range at the top of the page. This data refreshes each time the page is loaded.

<Frame>
  <img src="https://mintcdn.com/iru/vtXsax0ggvTiXavA/assets/media/images/iru-edr-devices-under-threat.png?fit=max&auto=format&n=vtXsax0ggvTiXavA&q=85&s=18fd3630e8ae08f167c0a5662597a35b" alt="Devices Under Threat metric on the Detections page" width="4000" height="772" data-path="assets/media/images/iru-edr-devices-under-threat.png" />
</Frame>

#### Filter by Date Range

On the **Detections** tab, click the date range at the top of the page to choose how far back threat events appear. The current range is shown to the right of **Viewing** and defaults to **Last 30 days**. Select a preset (**Last 24 hours**, **Last 7 days**, **Last 30 days**, **Last 60 days**, **Last 90 days**, or **All time**) or **Custom date range** for specific start and end dates. Your selection applies to the dashboard widgets and the detections table.

<Frame>
  <img src="https://mintcdn.com/iru/vtXsax0ggvTiXavA/assets/media/images/iru-edr-detections-last-x-days-filter.png?fit=max&auto=format&n=vtXsax0ggvTiXavA&q=85&s=f7d88691e920499415f87057127aae20" alt="Iru Endpoint Detections page with Last 30 days date range menu open next to Viewing, showing Last 24 hours through Custom date range" width="1188" height="736" data-path="assets/media/images/iru-edr-detections-last-x-days-filter.png" />
</Frame>

### Search, Filters, and the Detections Table

Above the detections table, use **Search** and the filter dropdowns to narrow the list by detection type, classification, status, severity, and other criteria.

<Frame>
  <img src="https://mintcdn.com/iru/vtXsax0ggvTiXavA/assets/media/images/iru-edr-detections-search-filters.png?fit=max&auto=format&n=vtXsax0ggvTiXavA&q=85&s=d355554abd78e6f76f7dffe4186f9f88" alt="Iru Endpoint Detections page showing Search field and filter dropdowns above the detections table" width="2948" height="176" data-path="assets/media/images/iru-edr-detections-search-filters.png" />
</Frame>

The **Detections List** (detections table) shows each threat event with columns such as threat name, classification, severity, detection date, number of affected devices, and status. Click a row to open the side panel with full details and response actions.

<Frame>
  <img src="https://mintcdn.com/iru/vtXsax0ggvTiXavA/assets/media/images/edr-threats-list.png?fit=max&auto=format&n=vtXsax0ggvTiXavA&q=85&s=4ed97c0106e6ccfc01274e26d4fba553" alt="Detections List (detections table) on the Detections page" width="4268" height="302" data-path="assets/media/images/edr-threats-list.png" />
</Frame>

### Threat Detail View

Click any threat event to open a side panel with detection and quarantine dates, file path, file hash, user information, and available response actions.

<Frame>
  <img src="https://mintcdn.com/iru/xTYPpu1SsBsdAQc_/assets/media/images/edr-threats-detail-view.png?fit=max&auto=format&n=xTYPpu1SsBsdAQc_&q=85&s=9174833cb6ad739e25418c8f4b98d675" alt="Endpoint Detection and Response EDR threat detail view" width="1860" height="1582" data-path="assets/media/images/edr-threats-detail-view.png" />
</Frame>

For investigation workflows, status changes, and response actions, see [Understanding Threat Events](/en/endpoint/endpoint-detection-response-edr/understanding-threat-events) and [Security Operations Actions in Endpoint Detection](/en/endpoint/endpoint-detection-response-edr/security-operations-actions-in-endpoint-detection).

### Device Record Detections Tab

The device record page shows the total number of threat events found on a specific device. To see the actual threat events, select the **Detections** tab.

<Frame>
  <img src="https://mintcdn.com/iru/vtXsax0ggvTiXavA/assets/media/images/iru-edr-detections-device-record.png?fit=max&auto=format&n=vtXsax0ggvTiXavA&q=85&s=0d1deec4962bacf0a95ea7250d82898c" alt="Endpoint Detection and Response EDR device record view" width="2420" height="932" data-path="assets/media/images/iru-edr-detections-device-record.png" />
</Frame>

Select any threat entry to display comprehensive details including detection timestamp, quarantine date, file location, cryptographic hash, and related user account information.

<Frame>
  <img src="https://mintcdn.com/iru/xTYPpu1SsBsdAQc_/assets/media/images/edr-threats-device-record-details.png?fit=max&auto=format&n=xTYPpu1SsBsdAQc_&q=85&s=3d80afbd15469a5135dafb12cc036bec" alt="Endpoint Detection Response overview showing EDR interface or configuration" width="836" height="1058" data-path="assets/media/images/edr-threats-device-record-details.png" />
</Frame>

For more details about how device views work, see [Device Views Overview](/en/endpoint/devices/device-views-overview).

### Platform-Specific Detections Features

<Tabs>
  <Tab title="macOS" icon="apple" iconType="brands">
    Iru Endpoint EDR categorizes file detections as malware, PUPs, benign, or unknown, and behavioral detections as malicious or suspicious.

    Use the **Detection type** filter on the detections table to show **File detections**, **Behavioral detections**, or both.

    The threat detail side panel provides [device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) for quarantining affected devices from the network.

    #### Rules Tab

    The **Rules** tab on the Detections page lets you configure behavioral detection rule groups and detection levels. From here you can set a global rule detection level or set detection levels per rule group (Cautious, Moderate, or Aggressive), and manage rule exceptions. For full details, see [Behavioral Detection Rule Groups](/en/endpoint/endpoint-detection-response-edr/behavioral-detection-rule-groups).

    <Frame>
      <img src="https://mintcdn.com/iru/vtXsax0ggvTiXavA/assets/media/images/iru-edr-rules-tab.png?fit=max&auto=format&n=vtXsax0ggvTiXavA&q=85&s=6fc47c195ac29b8680ec0397caac1874" alt="Rules tab on the Detections page" width="2962" height="910" data-path="assets/media/images/iru-edr-rules-tab.png" />
    </Frame>
  </Tab>

  <Tab title="Windows" icon="microsoft" iconType="brands">
    Windows EDR categorizes file detections as malware, PUPs, benign, or unknown.

    Use the **Classification**, **Severity**, and **Status** filters to investigate malware and PUP detections on enrolled Windows devices.
  </Tab>
</Tabs>

### Next Steps

* [Understanding Threat Events](/en/endpoint/endpoint-detection-response-edr/understanding-threat-events)
* [Security Operations Actions in Endpoint Detection](/en/endpoint/endpoint-detection-response-edr/security-operations-actions-in-endpoint-detection)
* [Configure the EDR Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-edr-library-item)
