To build attack maps, complete the initial portal configuration. Collect asset telemetry and connect your vulnerability scanner API.
Collect endpoint telemetry using the Trellix APD agent
Prerequisites: Configure your firewall to permit outbound access to the Trellix APD tenant.
Ensure the following rules are active:
NDR to trellix-apd.com on TCP Port 443.
NDR to trellix-apd.com on TCP Port 44305.
Endpoints to trellix-apd.com on TCP Port 44305.
Note
You must deploy the Trellix APD agent even if a vulnerability scanner is integrated. The agent discovers vital host and network telemetry needed to calculate risk. The platform cannot scan IP ranges or network segments.
The Trellix APD agent collects the following endpoint data:
Hostname and identifying information
Operating system version
Local users, groups, and group membership
User login history
Running processes
Network interface configuration
Listening ports
Authorized public SSH keys and PEM-derived keys
RDP client usage history
Commonly used desktop applications
Windows domain controllers, users, and groups
Log in to the Trellix APD portal.
Select the Scanning tab.
Download the script for your operating system.
The Windows script is named
deepsurface-windows-ephemeral.ps1The Linux script is named
deepsurface-linux-ephemeral.shThe macOS script is named
deepsurface-macos-ephemeral.sh
Open your command-line interface with administrator privileges on the endpoint.
Bypass the execution policy if the system blocks the script.
Run the script.
Note
The script automatically downloads the lightweight agent. The micro-agent requires 30MB RAM and 2 to 10MB of daily network bandwidth. The local scan typically completes in 2 to 5 minutes. The scanning status displays as “not applicable” until data processing is complete. The script is designed to run dormant on a schedule. Schedule scans weekly, daily, or hourly to minimize performance impact. Best practice involves using a remote endpoint management tool to schedule these scans. Data processing in the cloud requires 8 to 10 hours. View the processed intelligence in the Risk Insights tab.
Deploy the Trellix APD agent using Trellix ePolicy Orchestrator SaaS (ePO - SaaS)
If you are in North America, you can deploy the agent through Trellix ePO - SaaS.
Check the Trellix APD agent into the Trellix ePO SaaS repository.
Deploy the Trellix APD agent globally using the Trellix Agent.
Trellix ePO collects scan data from all endpoints in a staging area. It batches the data update to the APD cloud.
Note
Integration and deployment using ePO - On-prem is not available at this time.
Manual testing workflow
Follow these steps to manually start the job for testing purposes.
Go to the → page on the Trellix APD portal.
Click Process in the Process Scan Queue.
Enable the checkbox to run the next task in sequence when finished.
The system manually processes the inputs and imports the vulnerability data and risk analysis.
View the updated information on the Risk Insights page after all jobs complete.
Import vulnerability data from Tenable Security Center
Note
Tenable Security Center must use a publicly accessible IP address to synchronize with the cloud tenant. The portal retains imported vulnerability data for 30 days. You must re-import scans periodically.
Log in to the Trellix APD portal.
Select Settings.
Select Vulnerability Sources.
Select your Tenable environment. Options include Tenable.io, Tenable SaaS, or SecurityCenter Tenable.sc API.
Type the public hostname, administrative username, and password.
Select Save and Test Integration to verify communication with the tenant.
Select Import to pull scan results into the portal.