The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Analyze campaigns in Trellix Insights

Prev Next

Trellix Insights receives telemetry feeds from network security devices such as Intrusion Prevention System (IPS) and endpoint security devices such as ENS and EDR. If the telemetry contains IOCs such as file hashes, MD5, SHA256, or IP addresses, a campaign is detected, and Insights notifies you of the campaign detection.

You can perform a detailed analysis of the selected campaign in the following order. This will enable you to review the complete attack lifecycle and proactively increase the level of protection of your environment against the campaign attack.