The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Triage and hunt using filters

Prev Next

Use filters to reduce thousands of events to a smaller list of suspicious ones. You can apply filters to any column and combine multiple filters for more specific queries.

  • Hunt for Living-off-the-Land Binaries (LOLBins): Filter the Process Path column for common tools that attackers abuse, such as powershell.exe, cmd.exe, wscript.exe, or mshta.exe.

  • Isolate activity by user: Filter the User column for activity from a specific user account that is under investigation or for processes running as high-privilege accounts like NT AUTHORITY\SYSTEM.

  • Find processes in unusual locations: Filter the Process Path to look for executables running from non-standard directories, such as temporary folders (C:\Users\*\AppData\) or download locations.

  • Combine filters for specific results: Create a multi-filter query to isolate highly specific activity. For example, Process Path contains powershell.exe AND User is NT AUTHORITY\SYSTEM AND Parent Path is not C:\Windows\System32\services.exe.