The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Access threat details

Prev Next

Quickly drill down to threat details, file descriptions, and corresponding events for indicators of compromise (IOC) from external data sources, identified by cyber threat feeds.

  1. On the Trellix ESM console, select + Add Tab → Open Views → Default Views → Cyber Threat Indicators.

  2. On the time frame list, select the time period for the view.

  3. Filter by feed name or supported IOC data types.

  4. For events and flows related to the selected IOC, perform any standard view action, including:

    • Create or append to a watchlist.

    • Create an alarm.

    • Execute a remote command.

    • Create an incident.

    • Look around or last look around.

  5. Download the STIX xml file.

  6. Select events or flows and click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png to view the IOC details.

    In Details page you can view the IOC Description, Triggers (rules), Source Events, and Source Flows.