SOC analysts spend significant time investigating alerts and events. This includes gathering information from various sources to fully understand the cause and potential impact of the alerts and events.
Alert management automatically gathers and analyzes any additional information Trellix has on an alert. For example, an indicator of compromise and the threat group known to use it. This data enrichment attempts to answer key questions about the events in the alert, and presents the results in simple language. This saves you time and potentially limits the impact of the alert. It also enables a less experienced analyst to work on more complex alerts. For more information, see View intelligence on the alert.