The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Response

Prev Next

The response is newline terminated text base that is a combination of boundary tags, message header information and JSON message payload.

--Boundary_300_380661968_1587754355337
TS: 1587751687198
BTS: 1587751687198
MID: f9b04b28bf4c87f3
SID: app-processor
CID: baAHA18PHEgdx80GtPZyiI
AID: HX
TPC: HX_ALERTS
Content-Disposition: form-data; name="HX_ALERTS"; filename="HX"
Content-Type: application/binary

{"type":"alert","producer":"app-
processor","subtype":"PROCESS_TRACKER","data":{"_id":5,"agent":{"_id":"6Kk3YlsJus6dTm1E9zS3yc","url":"
/hx/api/v3/hosts/6Kk3YlsJus6dTm1E9zS3yc","containment_state":"normal"},"event_at":"2020-04-
24T18:07:20.115Z","matched_at":"2020-04-24T18:07:20.115Z","reported_at":"2020-04-
24T18:07:48.571Z","source":"PROCESS_TRACKER","subtype":null,"matched_source_alerts":[],"resolution":"A
LERT","is_false_positive":false,"decorators":[],"md5values":["cdea299dea8bc934eb375607633ded20"],"deco
rator_statuses":[],"url":"/hx/api/v3/alerts/5","condition":null,"indicator":null,"event_id":null,"even
t_type":null,"event_values":[{"id":"alert--ff8367cb-1451-4a1d-88b0-
e715dcf162ef","type":"alert","name":"Malicious Process cdea299dea8bc934eb375607633ded20
Started","alert_type":"PROCESS_TRACKER","action_nature":"tasking-immediate","description":"Malicious
Process cdea299dea8bc934eb375607633ded20 Started","start_time":"2020-04-
24T18:07:20.115Z","alert_context":["event--79920691-91a0-5345-b53a-39afe34db2da","finding--644ad639-
b5fa-49e0-968f-
1c7b556ca305"],"parameters":{"md5":"cdea299dea8bc934eb375607633ded20"},"object_status":"active","objec
t_source":"Endpoint","created":"2020-04-24T18:07:48.528Z","modified":"2020-04-
24T18:07:48.528Z"},{"id":"eventlog--9ac4b4a6-3af0-4641-93ce-
644a7771f9b8","type":"eventlog","extensions":{"cef-log-
ext":{"meta_information":{"categoryTechnique":"Malware","categoryDeviceType":"Process
Tracker","categoryTupleDescription":"Process Tracker found a compromise
indication","categoryOutcome":"Success","categoryBehavior":"Found","categorySignificance":"Compromise"
}}}},{"id":"file--79920691-91a0-5345-b53a-
39afe34db2da","type":"file","name":"RandomEvent.exe","file_extension":".exe","file_path":"C:\\Program
Files\\RandomEvent\\RandomEvent.exe","size_in_bytes":2272432,"file_created":"2016-10-
16T01:19:22.000Z","file_last_modified":"2016-10-16T01:20:22.000Z","file_last_accessed":"2016-10-
28T18:26:12.144Z","is_archive":true,"is_compressed":false,"is_encrypted":true,"is_hidden":false,"write
":true,"hashes":[{"hash_algorithm":"md5","value":"cdea299dea8bc934eb375607633ded20"}],"object_status":
"active","object_source":"Endpoint","created":"2020-04-24T18:07:48.528Z","modified":"2020-04-
24T18:07:48.528Z","owner_user":"BUILTIN\\Administrators","owner_group":"wheel","digital_signatures":["
digital-signature-info-type--0d9619a3-048e-4da4-8684-7c70b4208bf0"]},{"id":"file--2cca9aa5-a3a9-5969-
b2c8-
1b5a7e6f5a1e","type":"file","name":"explorer.exe","file_extension":".exe","file_path":"C:\\Windows\\ex
plorer.exe","object_status":"active","object_source":"Endpoint","created":"2020-04-
24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"process--2b652c42-970a-4720-bc40-
bc44de64a2f5","type":"process","pid":11864,"binary":"file--79920691-91a0-5345-b53a-
39afe34db2da","parent":"process--cc72747d-cd9d-4d29-b8f1-
ad93afc6bb86","object_status":"active","object_source":"Endpoint","created":"2020-04-
24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z","arguments":"\"C:\\Program
Files\\RandomEvent\\RandomEvent.exe\""},{"id":"process--cc72747d-cd9d-4d29-b8f1-
ad93afc6bb86","type":"process","pid":2032,"binary":"file--2cca9aa5-a3a9-5969-b2c8-
1b5a7e6f5a1e","object_status":"active","object_source":"Endpoint","created":"2020-04-
24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"finding--644ad639-b5fa-49e0-968f-
1c7b556ca305","type":"finding","risk_nature":"malicious","object_status":"active","object_source":"End
point","created":"2020-04-24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"software--
79920691-91a0-5345-b53a-
39afe34db2da","type":"software","name":"Enricher","object_status":"active","object_source":"Endpoint",
"created":"2020-04-24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"action--735adbdc-
6553-5b19-b6f4-2ceca35afafd","type":"action","name":"process-
start","action_nature":"observed","start_time":"2020-04-24T00:00:00.000Z","objects":["process--
2b652c42-970a-4720-bc40-
bc44de64a2f5"],"object_status":"active","object_source":"Endpoint","created":"2020-04-
24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"event--79920691-91a0-5345-b53a-
39afe34db2da","type":"event","event_type":"start","name":"process-event observed and
analyzed","start_time":"2020-04-24T00:00:00.000Z","objects":["file--79920691-91a0-5345-b53a-
39afe34db2da","process--2b652c42-970a-4720-bc40-bc44de64a2f5","finding--644ad639-b5fa-49e0-968f-
1c7b556ca305","software--79920691-91a0-5345-b53a-
39afe34db2da"],"object_status":"active","object_source":"Endpoint","created":"2020-04-
24T00:00:00.000Z","modified":"2020-04-
24T00:00:00.000Z","account_name":"FIREEYE\\matthew.tardiff"},{"id":"analysis--79920691-91a0-5345-b53a-
39afe34db2da","type":"analysis","name":"enrich-context","action_nature":"tasking-
immediate","is_automated":true,"performer":"software--79920691-91a0-5345-b53a-
39afe34db2da","parameters":{"hash":"cdea299dea8bc934eb375607633ded20"},"results":["finding--644ad639-
b5fa-49e0-968f-1c7b556ca305"]},{"id":"relationship--4baee7d9-d716-4ee3-beec-
e2d0508d0ab9","type":"relationship","source":"event--79920691-91a0-5345-b53a-
39afe34db2da","target":"analysis--79920691-91a0-5345-b53a-
39afe34db2da","relationship_type":"triggered"},{"id":"digital-signature-info-type--0d9619a3-048e-4da4-
8684-7c70b4208bf0","type":"digital-signature-info-
type","signature_verified":true,"signature_exists":true,"certificate_issuer":"C=US, S=Washington,
L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA
2011","certificate_subject":"sha256"}]}}
--Boundary_300_380661968_1587754355337