The Summary tab is the starting point to investigate the alert. It provides a high-level overview of the alert, allowing you to see its current state and priority. From here, you can pivot to view the events in the alert over time on the Alert Timeline tab and view any intelligence information on the Intel and MITRE tabs and take action to contain, mitigate, and remediate the alert on the Respond tab.
The Summary tab shows the following information:
The attack story: If you have integrated Trellix Wise with Helix, this section shows an AI generated analysis of the alert. It provides a summary of why the alert was triggered and what happened, which users or assets were affected, any available network or source information such as IP addresses, an assessment of whether the attack was successful and the evidence to justify this. Expand the Severity Criteria to see why Trellix Wise assigned the severity to the alert. When an alert is triggered, it can take several minutes for the Trellix Wise summary to appear.
How the alert was triggered: The source of each alert or event, such as endpoint, email, or network, and when events were first and last detected. For each alert or event, it shows the MITRE tactics and techniques that were used, and the group by field shows the attributes that link the alerts or events. This contextual information helps you understand the attack pattern, allowing you to take the appropriate action on the alert.
Which assets are affected: Host-based and network-based asset information from the alerts or events, and their containment status. For host-based alerts or events this is the asset name, and for network-based alerts or events this includes source IP addresses, destination IP addresses, usernames, and email addresses. If there is no host information, Helix analyzes the network data and uses either known information, or infers information from the data, to associate it with a known host. This improved data mapping gives a clearer picture of the impact of the attack in your environment.
What actions should I take: A list of suggested actions you can take on the alert. If integrated, Trellix Hyperautomation workflows and their status are shown. Otherwise, there is a list of suggested manual response actions you can take.