Below are provided some troubleshooting tips for gathering the proper data to determine whether you are dealing with a false positive or uninteresting event:
What did you expect to see? What is the vulnerability, if applicable, that the attack indicated by the alert is supposed to exploit?
Ensure that you capture valid traffic dumps that are captured from the attack attempt (for example, have packet logging enabled and can view the resulting packet log).
Determine whether any applications are suspected of triggering the alert — identify which type of applications, their versions, and the specific configurations.
If you intend to work with Trellix Technical Support on the issue, we ask that you provide the following information to assist in troubleshooting:
If this occurred in a lab using testing tools rather than live traffic, please provide detailed information of the attack/test tool used, including its name, version, configuration and where the traffic originated.
If this is a testing environment using a traffic dump relay, make sure that the traffic dumps are valid, TCP traffic follows a proper 3-way handshake, and so on.
Also, please provide detailed information of the test configuration in the form of a network diagram.
Export Alert Details and Packet Capture (within Attack Log).
Be ready to tell Technical Support how often you are seeing the alerts and whether they are ongoing.