This topic covers the following information:
ATI Alert Drill-Down view
From the Alerts > Alerts > Hosts page or the Alerts > Alerts > Alerts page, you can drill down from an ATI-badged alert to the threat intelligence developed by the Trellix Research Labs team.
You can click on the anchored links to display further details.
Automatic Updates to ATI Alerts
The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix DTI cloud. By default, the appliance automatically queries the DTI server for updated threat intelligence.
For more information, see Enabling or disabling ATI alert auto-updates using the CLI.
Sections Within the ATI Alert Details
Threat intelligence information for an ATI alert consists of an Event Summary section followed by additional sections of information, depending on what is known about the threat.
Event Summary
The Event Summary section displays the following information about the threat:
Name
Name of the malware object or malware callback event.
MD5 sum/URL
MD5 checksum that identified the malware object.
URL that identified the malware callback.
Threat Level
Level of risk, in terms of how damaging the attack can be, posed by the attack against the targeted organization: High, Medium, or Low. This score is based on the malware's behavioral capabilities and intent, threat actor profiles, and otherTrellix intelligence as available.
The Threat Level determination for an ATI alert is different from the Severity for any alert. The Severity estimates the likelihood that the targeted host has been compromised by an event. For example, established command and control (CnC) channels result in highest severity, while host connection to a compromised site is low severity because it does not indicate whether the host was breached.
NOTE: If the appliance is deployed in inline mode and the interface is configured for blocking mode, host connections to compromised sites can be blocked. For more information, see Inline monitoring.
Threat Type
Examples of threat types displayed in this field are listed below:
APT
Backdoor
Downloader
Exploit
Heuristic
Infostealer
Trojan
Worm
Attribution
Threat actor believed to have performed an act observed on your network.
Risk Summary
Description of the risk to your network.
Mitigation
This section lists threat mitigation information, if known.
Network Mitigation
Lists IP addresses or domains used in the attack. You might need to use this information to take action in other products, such as a web proxy or firewall.
Indicator of Compromise
Can include new files, modified registry keys, and system services created.
Software Mitigation
For threat type exploit only, this field lists the CVE and patch information.
Threat Life Cycle
This section lists threat life cycle elements, if known.
Installations
Installation activity performed on the victim machine.
Delivery
Method used to deliver the malware object or malware callback, such as Email Attachment or Web link.
C2
Command and control (CnC) instructions issued to the malware.
Malware Exploit Details
This section lists malware exploit details, if known.
Vulnerability Info
Lists of links to threat advisories.
Affected Software
List of software susceptible to the exploit.
Appendix
This section lists files installed by the attack, if known.