The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Identify all affected endpoints

Prev Next

You can create a list of every endpoint and server that a compromised account accessed.

  1. Use the Search username field to search for all activity associated with the compromised account.

  2. In the graph view, every connected hexagon represents a system the account logged into or attempted to log into.

  3. To compile a list of all unique hostnames and IP addresses, use the grid view. Filter or sort by the Src Host and Tgt Host columns. You can use the Export CSV function to save this list for your incident report.