It can be difficult to evaluate if an alert is a true positive that requires further investigation, or a false positive. Alert management uses multiple intelligence sources to automatically enrich the alert with any information Trellix has on the alert. The Intelligence column in the alert table shows the source of an alert, for more information click on an alert and select the Intelligence tab. If multiple intelligence sources have information on an alert, it can help reduce the likelihood of the alert being a false positive.
Prioritizing one alert over another of the same severity can also be difficult. On the Alerts page, the alerts table shows how many domains detected the alert, as well has how many assets are affected. It is likely that the more domains and assets are affected, the more serious the alert.
Alert management automatically provides a list of possible response actions you may want to take on the alert. This saves time investigating the alert, and may help to limit the impact of the alert.
As you work on an alert it is important to document your findings. This allows easy collaboration across the SOC team if the alert has to be escalated to a more senior analyst, and so on. You can add more detail and provide context about each action you took on the Notes tab. Otherwise, you would have to use a different tool to store this information, which could lead to important information being lost. You can associate a note with an event, artifact, or response action, or you can add a more general comment.
This workflow includes the following tasks:
View intelligence on the alert to evaluate if the alert needs further attention. See View intelligence on the alert.
Prioritize the alerts you need to work on. See Sorting and filtering alerts.
Document your findings. See Documenting and tracking alert activity.