The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Example workflow: Extend an investigation by looking beyond an alert and the metadata it provides to see all relevant information about a threat.

Prev Next

During an alert investigation, you suspect that an alert does not contain all relevant information about a threat. You start your investigation by reviewing intelligence information on the alert. You run an initial search, and use the search results to build other searches that deepen the investigation. When you are satisfied with the search query, you save the query so it could be used later. To ensure this type of activity will generate an alert, you create a new detection rule based on the search query.

This workflow includes the following tasks:

  1. Open an alert from the alert table, and then select the Intelligence tab. Note interesting artifacts, such as a hash or an IP address that is associated with a specific adversary or campaign.

  2. Read articles that discuss the adversary or campaign so you can learn more about them.

    Your research informs you about other techniques, tactics, and procedures you need to check in your environment.

  3. Build a query to find events that are related to the techniques, tactics, and procedures. See Creating a search query .

  4. Run the search. See Run a new search.

  5. Review the search results. See Working with search results.

  6. If the data suggests a true positive, look for key-value pairs that can refine or expand the search results, and run additional searches. See View raw event data in a separate panel.View raw event data in a side panel

  7. If the data suggests a false positive, acknowledge and suppress the alert. See Acknowledge alerts and Suppress alerts.

  8. Save the search. See Save a search.

  9. Create a rule based on the search query to ensure the activity generates alerts. See Create a rule from a search query.