The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Analysis tab

Prev Next

The Analysis tab on the Menu bar enables you to perform network and events analysis.

The following table gives a high-level overview of the tab tree and the available options.

Item

Description

Attack Log

Analyze the alerts detected by your network security appliances.

Threat Explorer

View the top attacks, attackers, targets, and malware within a given period of time and a direction.

Malware Files

Monitor the potential malware downloads on the network and to view or export the related file reports.

Callback Activity

Analyze the callback activities participating in the damage of the endpoints including the background of the bot, the time till it was active, the IP address involved, and similar other useful information such as the host name, the operating system, and the user details.

High-Risk Endpoints

Monitor the suspicious endpoints infected by the malware by providing the name of the endpoint, the user details, and the operating system of the endpoint.

Quarantine

View the list of endpoints quarantined for all the Sensors

MITRE ATTACK View

View and analyze attacks and alerts detected by your network security appliances in the MITRE ATT&CK matrix format.

Note

This option is not available in Trellix IPS Central Manager.

Event Reporting

Generate and view Custom and Traditional reports based on the analysis of the events and the network.