The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

ATI badges in the Web UI

Prev Next

This topic covers the following information:

Badge colors that indicate risk levels

When ATI is enabled, the Network Security Web UI visually flags an ATI alert—an MVX-verified event for which the appliance has obtained threat intelligence—by displaying a color-coded badge in the Alerts tab of the appliance. In the Alerts > Alerts > Alerts or Alerts > Alerts > Hosts page, if an alert grouping includes an ATI alert, the table row displays a Threat Info badge in the Badges column. You can click an ATI badge to display a filtered list of alerts. Clicking on an alert displays the Alert Details page.

The color of a Threat Info badge indicates the level of risk that the attack poses to your network:

Badge

Description

icon_badge_ati_3.png

A red Threat Info badge indicates an ATI alert for a threat that poses a high risk.

icon_badge_ati_2.png

An orange Threat Info badge indicates an ATI alert for a threat that poses a medium risk.

icon_badge_ati_1.png

An amber Threat Info badge indicates an ATI alert for a threat that poses a low risk.

Note

For managed Network Security appliances, ATI badges and ATI information are visible from the Central Management System appliance Web UI only.

ATI alert badges in the Alerts > Alerts > Hosts page

The Alerts > Alerts > Hosts page lists malware alerts and associated callback activity, grouped by source IP address and malware type. A Threat Info badge appears in a table entry if threat intelligence is known for an alert in the grouping.

The default display lists entries in reverse chronological order, shows 20 results per page, covers the previous 24 hours of network threat prevention processing, and is not filtered on any data column.

ATI alert badges in the Alerts > Alerts > Alerts page

The Alerts > Alerts > Alerts page lists malware alerts and associated callback activity, grouped by attack (source IP address, target IP address, and attack rule name). A Threat Info badge appears in a table entry if threat intelligence is known for an alert in the grouping.

The default display lists entries in reverse chronological order, shows 20 results per page, covers the previous 24 hours of network threat prevention processing, and is not filtered on any data column.