The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding filters

Prev Next

You can set filters based on your requirement in the MITRE ATTACK View page that provide you the capability to drill down into the attack details, learn more about the adversarial behavior, and nature of the cyber attack.

When you navigate to Analysis → <Admin Domain Name> → MITRE ATTACK View, it displays the matrix table and related data only for matching attacks for the time period set in the page. No filter criteria is set at this point of time. You can add one or more filters by performing the steps given below:

Steps:

  1. On the Analysis tab, select the required domain from the Domain drop-down list in the left pane, and open the MITRE ATTACK View page.

  2. Click GUID-6E92D498-1A6F-4135-8E3B-9F11A97186B5-low.png button.

    Add Filter Criterion dialog-box appears.

    Add Filter Criterion dialog
    Add Filter Criterion dialog


  3. Enter the values in the following fields:

    • Filter On — Select Attack Severity or IP Address from the drop-down list.

    • Value — Enter the specific value as per the filter chosen. For IP address selected as the filter, you can manually enter any IPv4 or IPv6 IP address that you want to examine including attacker IP and target IP. For Attack Severity selected as the filter, you can choose Informational, High, Medium or Low from the Value drop-down list.

    Note

    You can apply one or more IP addresses or attack severity levels as filters.

  4. Click Save.

    The page reloads and shows tactics, techniques, and sub-techniques in the Mitre matrix table format for the matching attacks based on the filter(s) applied. For example, the figure below shows the filtered data on the MITRE ATTACK View page after IP 11.1.1.18 and attack severity level High have been applied as filters.

    The page view after applying IP and attack severity filters
    The page view after applying IP and attack severity filters