The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Real-Time indicator detection

Prev Next

Threat activity intelligence is collected by Trellix and made available to the Endpoint Security (HX) products as indicators of compromise (also referred to as indicators or IOCs) through Trellix 's Dynamic Threat Intelligence (DTI) cloud.

Endpoint Security uses the Real-Time Indicator Detection (RTID) feature to detect suspicious activities on your host endpoints. RTID monitoring uses Trellix indicators to detect the following:

  • Unauthorized use of valid accounts

  • Trace evidence and partial files

  • Command and control activity

  • Known and unknown malware

  • Suspicious network traffic

  • Valid programs used for malicious purposes

  • Unauthorized file access

See "Real-Time Indicator Detection" in the Endpoint Security (HX) Server User Guide for more information.