The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alerts grouped by victim IP addresses

Prev Next

This topic covers the following information:

  • About the Hosts tab

  • Fields in the Hosts tab

  • Details for a victim-specific alert grouping on

About the Hosts tab

An IPS platform offers three views of malware events. Two of the views list malware alerts (both MVX-verified malware events and MVX-correlated IPS events), and the third view lists callback activity associated with malware. When you choose Alerts > Alerts, the Hosts tab is selected by default.

The Hosts tab lists all malware alerts and IPS alerts, grouped by victim IP address and attack rule name. Multiple alerts associated with the same victim and signature rule are combined in a single entry in the list. The Total field displays the number of alerts represented by an entry.

Fields in the Hosts tab

The Hosts tab lists MVX-verified events that occurred within the selected time frame, consolidated by victim IP address, and sorted in reverse chronological order. On an IPS platform, the list includes IPS events and can include acknowledged IPS alerts.

The following table describes the fields in this view alerts grouped by victim.

Column

Description

ctrl_ips_drill-down_ips.png

Click to expand the row to display additional results

Host

IP address of the infected host.

Severity

The icon represents the event severity level. Event severity estimates the likelihood that the targeted host was compromised by the event. The following types of icons are used:

icon_ips_severity_critical_7.png

A row of 7 to 10 red dots indicates a Critical severity (levels 7 ‑ 10).

icon_ips_severity_major_4.png

A row of 4 to 6 orange dots indicates a Major severity (levels 4 ‑ 6).

icon_ips_severity_minor_1.png

A row of 1 to 3 amber dots indicates a Minor severity (levels 1 ‑ 3).

Total

Total number of malware alerts (infections and callbacks) and IPS alerts for this infected host. If you want to go to a view of the Alerts tab that has been filtered to show the individual alerts for the infected host, click the linked text.

Infections

Number of infections for this host.

Callbacks

Number of malware callback infections for this host, including signature matches and communications with the botnet server.

Blocked

Number of events that were blocked by appliance inline blocking.

Last malware

Last type of malware or attack involved in this infected host. To display a detailed description of this type of attack, click the linked text. Detailed descriptions are not available for attacks detected by custom IPS rules.

Last seen at

Date and time of the most recent attack on the host.

Host name

Last host name associated with the network host that sent the attack, if known.

Last acknowledgement at

Date and time of the most recent acknowledgment of this alert

Badges

On an IPS platform, this column displays badges that indicate analysis of alerts represented by the entry:

icon_badge_ips.png

The IPS badge means that the entry represents one or more IPS alerts. For more information, see the following topics:

● Malware events and IPS events

● About the IPS Events Page

● IPS event and alert management

icon_badge_data-theft.png

The Data Theft badge means that the entry represents one or more non-IPS alerts in which data theft occurred. If you want to go to a view of the Hosts tab that has been filtered to list the individual alerts for the infected host, click the badge. For more information, see the Network Security User Guide.

Badges

On any Network Security appliance enabled for Advanced Threat Analysis (ATI), Threat Info badges can appear in this column. The color of the badge indicates the level of risk that the threat poses to your network.

icon_badge_ati_3.png

A red badge indicates an ATI alert for a threat that poses a high risk.

icon_badge_ati_2.png

An orange Threat Info badge indicates an ATI alert for a threat that poses a medium level of risk.

icon_badge_ati_1.png

An amber Threat Info badge indicates an ATI alert for a threat that poses a low risk to your network.

For managed Network Security appliances, ATI badges and ATI information are visible from the Central Management System Web UI only. For more information about ATI, see the Network Security User Guide.

For an ATI alert, the threat level measures the level of risk posed by the attack against the targeted organization. This score is based on the malware's behavioral capabilities and intent, threat actor profiles, and other FireEye intelligence as available.

The ATI threat level determination for an ATI alert is different from the threat severity for an alert. The severity estimates the likelihood that the targeted host has been compromised by an event. For example, established command and control (CnC) channels result in highest severity, while host connection to a compromised site is low severity because it does not indicate whether the host was breached.

Times are displayed in UTC format by default. To set the time zone, choose Settings > Date and Time.

You can filter the list on a single column. Click Show / Hide Filters to show or hide filter options for each column.

  • To filter the list on one or more types of badges, open the Select Badge(s) list, select the types of badges you want to include, then click Apply.

  • For all other columns, type the text you want to match and then press Enter.

Details for a victim-specific alert grouping

To display detailed information about any entry listed in the Hosts tab, you can expand the view of the entry by clicking the triangle icon in the left-most column of that row. The drill-down view displays the following information about the infected host (attack victim):

Field

Description

Malicious capabilities observed in the VM

Data theft

Number of items that were stolen or targeted for theft.

Malicious behavior

Type of malware activity that is observed.

OS change summary

Operating system changes that are made by the malware.

Malware detected

Malware

Type of malware involved in the infection.

Severity

Severity level of the event.

Total

Total number of alerts involving the specified malware family. Click the link to display a list of individual alerts on this host that are related to the same malware family.

Infections

Number of infections that are confirmed on the MVX engine.

Callbacks

Number of events that involved communication with a remote command and control (CnC) server.

Blocked

Number of events that were blocked by appliance inline blocking.

Botnets

Number of events involving botnets.

Last CnC server

Remote CnC server.

Last location

CnC server location, if known.

First seen

First time that an infection event for this malware family was recorded for this host.

Last seen

Last time that an infection event for this malware family was recorded for this host.

Ports used

Ports used in the attack.

Protocols

Protocols used in the attack.

Infection URLs (the first 10 URLs that infected the victim)

ctrl_ips_drill-down_ips.png

Click the arrow to the left of a URL to display the URLs to which the user was directed as a result of the initial infection. The original (first) URL that was visited is shown in bold.

Initial infection URL

Original (first) URL visited by the victim.

# Visits

Number of times the infected host has visited the same infection URL

Total URLs

Total number of URLs to which the user was redirected.

First URL at

Time at which the first URL was reached.

Last URL at

Time at which the last URL was reached.

Malware binaries (the first 10 URLs that infected the victim)

Md5sum

MD5 checksum result. Expand for protocol headers.

Filetype

Type of file analyzed from the traffic stream. File types include the following:

  • DLL (Dynamic Link Library)

  • Archived files (ZIP, RAR, TNEF, and 7-ZIP)

  • XFF (X-Forwarding)

  • XOR (eXclusive-OR encoded) obfuscated Web objects

  • TCP Reset and Out-of-Band Blocking

For more information, see the Network Security User Guide.

Protocol

Protocol involved.

Encoding

Encoding used.

Last analysis time

Most recent time when the checksum was performed.

# Occurrences

Number of checksum activities.

Acknowledge the infections and callbacks above for the host at ip‑address

ctrl_ips_drill-down_ips.png

Click to expose the notes text box and the Acknowledge button for this alert. For more information about acknowledging an IPS alert, see the Network Security User Guide.