The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Analyze High-Risk Endpoints

Prev Next

You can view and analyze the endpoints whose behavior on the network is consistent with malware infection and callback activity. From the dashboard, view the Top High-Risk Endpoints that gives you details of endpoints whose behavior on the network is consistent with malware infection. On clicking an endpoint on the Top High-Risk Endpoints dashboard, you are directed to the Analysis → High-Risk Endpoints page. This page displays the details of the endpoints identified as risky to your network.

Top High-Risk Endpoints monitor
Top High-Risk Endpoints monitor


You can analyze the details of risky endpoints, such as IP address, DNS name, OS, the user details, the endpoint risk which is determined by the attacks, and certain behavioral indicators. You can view the count of the attacks per malware phase. These are classified as Exploits, Infections, and Callbacks.

You can further drill-down to view the details of these attacks, such as time of the attack, detailed attack description, name of the attack, and the result of the attack on your network. You can further download the packet log to analyze the affected data packets, obtain the attacker forensics and the target forensics, and view the direction of the traffic on which the attack is detected – whether inbound or outbound. The target and attacker details, such as, the IP address, country and the port can also be viewed. You can view these information specific to any admin domain by selecting the required admin domain from the Domain drop-down list. The data is calculated based on the admin domain selected and will change for each admin domain and the corresponding child domains selected.

You can analyze the behavioral risks, such as patterns and Endpoint Threat Factor (ETF) and the occurrence of the last event. The patterns value indicates the risk of the endpoint based upon attack patterns. For example, a spike in certain attacks or groups of attacks to or from this endpoint over a given time period would increase its patterns value and therefore its overall endpoint risk. The ETF is a value assigned by Trellix IPS to internal endpoints to indicate their risk to the network. Multiple components are considered to determine the value, including reputation of endpoints with which it is communicating, and the number and severities of alerts it has generated. The ETF is in turn used to influence the overall endpoint risk.

Note

Data displayed in the Top High-Risk Endpoints monitor is automatically refreshed by the Manager on an hourly basis. This is not user configurable.

High-Risk Endpoints
High-Risk Endpoints


Attack Log

Upon double-clicking on the endpoint IP address, the Attack Log page opens. You can analyze and view alerts related to the selected endpoint IP address.

High-Risk Endpoint related alerts in Attack Log
High-Risk Endpoint related alerts in Attack Log


To close the attack log, click Back or GUID-5D9E9726-BCE1-4146-9C19-849060FE6C60-low.png icon.

The following table shows the information displayed in the High-Risk Endpoints section.

Option

Definitions

Endpoint Risk

Specifies the risk based on the attacks and certain behavioral indicators. The risk is displayed with an icon and a risk score. The icon and score details are as follows:

  • Dark red icon — Very high risk (Risk score above 180)

  • Red icon — High risk (Risk score ranges between 140 and 180)

  • Orange icon — Medium ( Risk score ranges between 100 and 140)

Note

Low scores in the range of 20–100 are not displayed on the dashboard for a endpoint.

Endpoint

Specifies the endpoint IP address

DNS Name

DNS name of the endpoint to resolve the names to IP addresses

OS

Operating system platform of the endpoint

User

Operating system user name of the endpoint

Attacks per Malware Phase

Specifies the count of the attacks per malware phase

  • Exploits — Specifies the number of attacks which have compromised the system. These are detected by the signature set.

  • Infections — Specifies the number of attacks which are detected in the form of malware files being downloaded by the endpoint

  • Callbacks — Specifies the count of callback attacks where an infected endpoint tries to communicate with the C&C server

Behavioral Risks

  • Patterns — Indicates the risk of the endpoint based upon attack patterns

  • ETF — A value assigned by Trellix IPS to internal executables to indicate their risk to the network

Last Attack

Specifies the date and time of the last event that affected the endpoint

Comment

Specifies any details or additional information about the endpoint activity

'Selected endpoint'

This tab displays various events related to a selected endpoint identified as risky to your network.

  • Endpoint Information

    The Endpoint Information sub-tab shows the following details specific to the endpoint.

    Endpoint Information sub-tab
    Endpoint Information sub-tab


    Option

    Definitions

    Country

    Country of the endpoint

    DNS Name

    DNS name of the endpoint to resolve the names to IP addresses

    NetBIOS Name

    NetBIOS name of the endpoint to access the endpoint machines

    Operating System

    Operating system platform of the endpoint

    Device Type

    Device type of the attacker/target

    MAC Address

    MAC address of the endpoint

    Domain/Workgroup

    Domain or workgroup of the endpoint

    User

    Operating system user name of the endpoint

    Data Source

    Point product (ePO) from where information is retrieved

    Trellix Agent Check-In Time

    Check-in time of the Trellix Agent that communicates with the same ePO server integrated with the admin domain

    Endpoint Type

    Type of the endpoints:

    • UNMANAGED (No Agent)— This indicates that there is no Trellix Agent installed on the endpoint.

    • UNMANAGED (MANAGED)— This indicates that the endpoint has a Trellix Agent but there is no active communication channel between the Agent and ePO server integrated with the admin domain.

    • MANAGED — This indicates that the endpoint has a Trellix Agent and there is active communication channel between the Agent and ePO - On-prem server integrated with the admin domain. The endpoint is managed by the agent.

    Installed products

    List of the installed products

    • Threat Explorer

      • Explore as attacker IP — Explore the threats where the endpoint is the source IP address.

      • Explore as target IP — Explore the threats where the endpoint is the destination IP address.

        For more information, see the section Threat Explorer.

    • Quarantine — Use this option to block all the traffic originating from the specified IP address seen on the selected device for the selected time.

      Quarantine Endpoint dialog
      Quarantine Endpoint dialog


      To quarantine endpoints to block all the traffic originating from the specified IP address:

      Properties option definitions

      Option

      Definition

      IP Address

      Enter the IP address of the endpoint.

      Device

      Select the specific device of the endpoint whose traffic originating from the IP address you want to block.

      Quarantine Duration

      Select the quarantine duration from the drop-down list.

      Remediate

      Select the checkbox to redirect the configured endpoint to the configured remediation portal.

      Note

      You can configure the remediation portal settings in Devices → Global → IPS Device Settings → Quarantine → Remediation Portal.

      Remediation cannot be applied for IPv6 address. The checkbox and the information icon for remediation is not displayed if you enter an IPv6 address in the IP Address field.



      Click Quarantine. The endpoint is added and displayed in the Quarantine page.

    • Tag (in ePO)— Use this option to assign a tag to the selected endpoint in ePO - On-prem.

      You are able to assign tags only to endpoints whose Endpoint Type denotes MANAGED. This means that the endpoint runs a suitable version of Trellix Agent and is managed by ePO - On-prem.

      To assign a tag:

      1. Select a tag from the drop-down list. If the tag you looking for does not appear in the list, click the refresh button.

      2. Click Tag.

        If the tagging is successful you receive a message stating its success. If not, you receive a failure notification.

  • ePO Threat Events

    The ePO Threat Events sub-tab displays the latest 50 Threat Events listed in the ePolicy Orchestrator - On-premises for a selected endpoint. The information displayed under this sub-tab includes the date and time at which the threat event was generated, the ID associated with the event, the event description, event category, action taken on the event, and the type of the threat that triggered the event.

    You can click the GUID-697C5B89-2CC8-4E8F-9BAE-69ED70CF8B3F-low.png icon to refresh the list and view the latest 50 Threat Events listed in the ePolicy Orchestrator - On-premises for the selected endpoint. The Search text field allows you to search for a specific event based on the Event Received Time, Event ID, Event Category and Threat Type. For example, to view all events associated with the Event ID 1095, type 1095 in the Search field.

    Note

    The sub-tab has Any Severity filter selected by default. With this filter selected, the sub-tab displays all types of events including those which are informational and/or of low-severity. Such events act as noise and impede one's ability to find true threats. To exclude these events, select the Warning+ Severity Only filter from the drop-down menu. This displays only those events with Critical, Alert and Warning severity.

    Note

    Ensure that the ePO server has the latest Trellix IPS Extension file installed. For information on how to download and install the Trellix IPSExtension, see the section Install Trellix IPS extension file in ePO - On-prem in Trellix Intrusion Prevention System Integration Guide.

    ePO Threat Events sub-tab
    ePO Threat Events sub-tab