The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Cyber threat

Prev Next

You can retrieve indicators of compromise (IOC) from remote sources and quickly access related IOC activity in your environment.

Cyber threat management enables you to set up automatic feeds that generate watchlists, alarms, and reports, giving you visibility to actionable data. For example, you can set up a feed that automatically adds suspicious IP addresses to watchlists to monitor future traffic. That feed can generate and send reports indicating past activity. Use GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png → Cyber Threat Indicators or on the Trellix ESM console use + Add Tab → Open Views → Default Views → Cyber Threat Indicators to drill down quickly to specific events and activity in your environment.

Supported IOC types

When you add a manual upload cyber threat feed, Trellix ESM sends the Structured Threat Information eXpression (STIX) file to the Indicator of Compromise (IOC) engine to be processed. If the file doesn't contain an IOC that is normalized for Trellix ESM, you receive an error message.

Indicator types normalized for Trellix ESM

Indicator type

Watchlist type

Email Address

To, From, Bcc, Cc, Mail_ID, Recipient_ID

File Name, File Path

File_Path, Filename, Destination_Filename, Destination_Directory, Directory

(Flows) IPv4, IPv6

IPAddress, Source IP, Destination IP

(Flows) MAC Address

MacAddress, Source MAC, Destination MAC

Fully qualified domain name, Host Name, Domain Name

Host, Destination_Hostname, External_Hostname, Domain, Web_Domain

IPv4, IPv6

IPAddress, Source IP, Destination IP, Attacker_IP, Grid_Master_IP, Device_IP, Victim_IP

MAC Address

MacAddress, Source MAC, Destination MAC

MD5 Hash

File_Hash, Parent_File_Hash

SHA1 Hash

SHA1

Subject

Subject

URL

URL

User name

Source User, Destination User, User_Nickname

Windows Registry Key

Registry_Key, Registry.Key (Registry subtype)

Windows Registry Value

Registry_Value, Registry.Value (Registry subtype)