The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

About custom IOC feeds

Prev Next

The appliance can receive indicators of compromise (IOCs) from the following custom feeds:

  • DTI feeds provide files from Trellix's Dynamic Threat Intelligence (DTI) cloud.

  • Third-party feeds send files from a third-party (non-Trellix) product.

The following types of IOCs can be uploaded to appliances:

  • IP address indicators—IP addresses of suspicious or known malicious remote hosts.

  • URL indicators—Suspicious or known malicious URLs and RegEx URLs.

  • Hash files—MD5 or SHA-256 hashes for suspicious or known malicious files.

  • Domain indicators—Names of suspicious or known malicious domains.

You can create a flat-file list for each indicator type, or you can combine different types of indicators into a standard format called STIX (Structured Threat Information Expression).

IOCs received from third-party feeds can be combined into a custom blacklist, and the appliance can block or allow traffic that matches indicators in the custom blacklist. If traffic is blocked, you are notified that a block action was performed. If traffic is not blocked, an alert is created and you are notified that a match occurred.