The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Core attribute

Prev Next

Select the core attribute as Attacker IP Address and click the hyperlink to view the following details:

  • Endpoint Information

  • ePO Threat Events

    Note

    The ePO Threat Events tab appears by clicking the Optional Tabs drop-down and selecting ePO Threat Events check-box.

Endpoint Information

The additional information displayed in the Endpoint Information section is shown in the following table.

Item

Description

Country

Country of the endpoint

DNS Name

DNS name of the endpoint to resolve the names to IP addresses

NetBIOS Name

NetBIOS name of the endpoint to access the host machines

Operating system

Operating system platform of the endpoint

Device Type

Type of the Sensor (for example, IPS Sensor)

MAC Address

MAC address of the endpoint

Domain/Workgroup

Domain or workgroup of the endpoint

User

Operating system user name of the endpoint

Data Source

Database tables from where information is retrieved

Trellix Agent Check-In Time

Check-in time of the Trellix Agent that communicates with the same ePO server integrated with the admin domain

Endpoint Type

Type of endpoint:

  • UNMANAGED (No Agent) — This indicates that there is no Trellix Agent installed on the endpoint.

  • UNMANAGED (MANAGED) — This indicates that the endpoint has a Trellix Agent but there is no active communication channel between the Agent and ePO server integrated with the admin domain.

  • MANAGED — This indicates that the endpoint has a Trellix Agent and there is active communication channel between the Agent and ePO - On-prem server integrated with the admin domain. The endpoint is managed by the agent.

Installed products

List of the installed products

The Endpoint Information sub-tab shows the following details specific to the endpoint.

  • Quarantine — Use this option to block all the traffic originating from the specified IP address seen on the selected device for the selected time.

    Quarantine Endpoint dialog
    Quarantine Endpoint dialog


    To quarantine endpoints to block all the traffic originating from the specified IP address:

    Option

    Definition

    IP Address

    Enter the IP address of the endpoint.

    Device

    Select the specific device of the endpoint whose traffic originating from the IP address you want to block.

    Quarantine Duration

    Select the quarantine duration from the drop-down list.

    Remediate

    Select the checkbox to redirect the configured endpoint to the configured remediation portal.

    Note

    You can configure the remediation portal settings in Devices → Global → IPS Device Settings → Quarantine → Remediation Portal

    Remediation cannot be configured for IPv6 address. The checkbox and the information icon for remediation is not displayed if you enter an IPv6 address in the IP Address field.

    Click Quarantine. The endpoint is added and displayed in the Quarantine page.

  • Tag (in ePO)— Use this option to assign a tag to the selected endpoint in ePO - On-prem.

    You are able to assign tags only to endpoints whose Endpoint Type denotes MANAGED. This means that the endpoint runs a suitable version of Trellix Agent and is managed by ePO - On-prem.

    To assign a tag:

    1. Select a tag from the drop-down list. If the tag you looking for does not appear in the list, click the refresh button.

    2. Click Tag.

      If the tagging is successful you receive a message stating its success. If not, you receive a failure notification.

ePO Threat Events

The ePO Threat Events sub-tab displays the latest 50 Threat Events listed in the ePolicy Orchestrator - On-premises for a selected endpoint. The information displayed under this sub-tab includes the date and time at which the threat event was generated, the ID associated with the event, the event description, event category, action taken on the event, and the type of the threat that triggered the event.

You can click the GUID-697C5B89-2CC8-4E8F-9BAE-69ED70CF8B3F-low.png icon to refresh the list and view the latest 50 Threat Events listed in the ePolicy Orchestrator - On-premises for the selected endpoint. The Search text field allows you to search for a specific event based on the Event Received Time, Event ID, Event Category and Threat Type. For example, to view all events associated with the Event ID 1095, type 1095 in the Search field.

Note

The sub-tab has Any Severity filter selected by default. With this filter selected, the sub-tab displays all types of events including those which are informational and/or of low-severity. Such events act as noise and impede one's ability to find true threats. To exclude these events, select the Warning+ Severity Only filter from the drop-down menu. This displays only those events with Critical, Alert and Warning severity.

Note

Ensure that the ePO server has the latest Trellix IPS Extension file installed. For information on how to download and install the Trellix IPSExtension, see the section Install Trellix IPS extension file in ePO - On-prem in Trellix Intrusion Prevention System Integration Guide.

ePO Threat Events sub-tab
ePO Threat Events sub-tab