The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alerts grouped by attack rule names

Prev Next

This topic covers the following information:

  • About the alerts Tab

  • Fields in the alerts Tab

  • Details for a rule-specific alert grouping

About the Alerts tab

An IPS platform offers three views of malware events. Two views list malware alerts (both MVX-verified malware events and MVX-correlated IPS events), and the third view lists callback activity associated with malware. When you choose Alerts > Alerts, the Hosts tab is selected by default.

To view the alerts grouped by attack rule name, click the Alerts link in the control bar.

The Alerts tab lists all malware alerts and IPS alerts, grouped by attack rule name only. Multiple alerts associated with the same signature rule are combined in a single entry in the list.

Fields in the Alerts tab

The Alerts tab lists MVX-verified events that occurred within the selected time frame, consolidated by attack rule name only, and sorted in reverse chronological order. On an IPS platform, the list includes IPS events and can optionally include acknowledged IPS alerts.

The following table describes the fields in this view of alerts grouped by attack

Column

Description

ctrl_ips_drill-down_purple_triangle.png

If the entry represents multiple alerts, click the purple triangle to show the individual alerts in the grouping rather than the alert grouping.

ctrl_ips_drill-down_ips.png

Click the gold triangle to expand the row to display additional results.

Type

Attack detection type:

• Domain Match—Domain matching on DNS requests.

• Infection Match—Pattern matching from a full or partial URL.

• Malware Callback—Communication with a botnet server.

• Malware Object—Local MVX engine rule matches a URL, an MD5 checksum, or both.

• Web Infection—Local MVX engine rule matches a URL.

ID

System-internal identification number for the alert. To display detailed information about this alert, click the linked text.

FT

Type of file analyzed from the traffic stream. File types include the following:

• DLL (Dynamic Link Library)

• Archived files (ZIP, RAR, TNEF, and 7-ZIP)

• XFF (X-Forwarding)

• XOR (eXclusive-OR encoded) obfuscated Web objects

• TCP Reset and Out-of-Band Blocking

For more information, see the Network Security User Guide.

Malware

Name of malware or attack.

Severity

The icon represents the event severity level. Event severity estimates the likelihood that the targeted host was compromised by the event. The following types of icons are used:

icon_ips_severity_critical_7.png

A row of 7 ‑ 10 red dots indicates acriticalseverity level (threat score 7 ‑ 10).

icon_ips_severity_major_4.png

A row of 4 ‑ 6 orange dots indicates amajorseverity level (threat score 4 ‑ 6).

icon_ips_severity_minor_1.png

A row of 1 ‑ 3 gold dots indicates aminorseverity level (threat score 1 ‑ 3).

Time

Date and time of the most recent occurrence of the attack.

Source IP

IP address of the victim that received the attack.

This address corresponds to the Attacked Port and Src IP fields in the drill-down view.

Target IP

IP address of the attacker.

URL/MD5sum

URL or MD5 checksum that triggered the Malware Object or Web Infection alert.

Location

Location in which the server is located, if known. This column is displayed only if geo-location data is loaded.

SC Version

Version number of the security content that was in use when the event occurred.

Badges

On an IPS platform, this column displays badges that indicate analysis of alerts represented by the entry:

icon_badge_ips.png

The entry represents one or more IPS alerts. For more information, see the following topics:

• Malware Events and IPS Events

• About the IPS Events Page

• IPS Event and Alert Management

icon_badge_data-theft.png

The entry represents one or more non-IPS alerts in which data theft occurred. In the Alerts tab, Data Theft badges are not hyperlinked. For more information, see the Network Security User Guide.

On any Network Security appliance enabled for Advanced Threat Analysis (ATI), Threat Info badges can appear in this column. The color of the badge indicates the level of risk that the threat poses to your network:

icon_badge_ati_3.png

A red badge indicates an ATI alert for a threat that poses a high risk.

icon_badge_ati_2.png

An orange badge indicates an ATI alert for a threat that poses a medium level of risk.

icon_badge_ati_1.png

An amber badge indicates an ATI alert for a threat that poses a low risk to your network.

For managed Network Security appliances, ATI badges and ATI information are visible from the Central Management System Web UI only. For more information about ATI, see the Network Security User Guide.

For an ATI alert, the threat level measures the level of risk posed by the attack against the targeted organization. This score is based on the malware's behavioral capabilities and intent, threat actor profiles, and other FireEye intelligence as available.

The ATI threat level determination for an ATI alert is different from the threat severity for an alert. The severity estimates the likelihood that the targeted host has been compromised by an event. For example, established command and control (CnC) channels result in highest severity, while host connection to a compromised site is low severity because it does not indicate whether the host was breached.

Times are displayed in UTC format by default. To set the time zone, choose Settings > Date and Time.

You can filter the list on a single column. Click Show / Hide Filters to show or hide filter options for each column.

  • To filter the list on one or more types of badges, open the Select Badge(s) list, select the types of badges you want to include, then click Apply.

  • For all other columns, type the text you want to match and then press Enter.

Details for a rule-specific alert grouping

For any entry in the Alerts tab, click the arrow to expand the view and display the following types of attack information, based on event type. For more information, see the Network Security User Guide.

  • Analysis Details

  • Attempted Infection Communication

  • Bot Communication Details

  • Callback Communication from Infected Host

  • Callback Communication Observed from the MVX Engine

  • Malware Detected

  • Malware Binaries

  • OS Change Details