The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

ATI Alert Details in the Web UI

Prev Next

This topic covers the following information:

ATI Alert Drill-Down view

From the Alerts > Alerts > Hosts page or the Alerts > Alerts > Alerts page, you can drill down from an ATI-badged alert to the threat intelligence developed by the Trellix Research Labs team.

You can click on the anchored links to display further details.

Automatic Updates to ATI Alerts

The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix DTI cloud. By default, the appliance automatically queries the DTI server for updated threat intelligence.

For more information, see Enabling or disabling ATI alert auto-updates using the CLI.

Sections Within the ATI Alert Details

Threat intelligence information for an ATI alert consists of an Event Summary section followed by additional sections of information, depending on what is known about the threat.

Event Summary

The Event Summary section displays the following information about the threat:

Name

Name of the malware object or malware callback event.

MD5 sum/URL

MD5 checksum that identified the malware object.

URL that identified the malware callback.

Threat Level

Level of risk, in terms of how damaging the attack can be, posed by the attack against the targeted organization: High, Medium, or Low. This score is based on the malware's behavioral capabilities and intent, threat actor profiles, and otherTrellix intelligence as available.

The Threat Level determination for an ATI alert is different from the Severity for any alert. The Severity estimates the likelihood that the targeted host has been compromised by an event. For example, established command and control (CnC) channels result in highest severity, while host connection to a compromised site is low severity because it does not indicate whether the host was breached.

NOTE: If the appliance is deployed in inline mode and the interface is configured for blocking mode, host connections to compromised sites can be blocked. For more information, see Inline monitoring.

Threat Type

Examples of threat types displayed in this field are listed below:

  • APT

  • Backdoor

  • Downloader

  • Exploit

  • Heuristic

  • Infostealer

  • Trojan

  • Worm

Attribution

Threat actor believed to have performed an act observed on your network.

Risk Summary

Description of the risk to your network.

Mitigation

This section lists threat mitigation information, if known.

Network Mitigation

Lists IP addresses or domains used in the attack. You might need to use this information to take action in other products, such as a web proxy or firewall.

Indicator of Compromise

Can include new files, modified registry keys, and system services created.

Software Mitigation

For threat type exploit only, this field lists the CVE and patch information.

Threat Life Cycle

This section lists threat life cycle elements, if known.

Installations

Installation activity performed on the victim machine.

Delivery

Method used to deliver the malware object or malware callback, such as Email Attachment or Web link.

C2

Command and control (CnC) instructions issued to the malware.

Malware Exploit Details

This section lists malware exploit details, if known.

Vulnerability Info

Lists of links to threat advisories.

Affected Software

List of software susceptible to the exploit.

Appendix

This section lists files installed by the attack, if known.