The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Handling false positive IoC alerts or logs

Prev Next

IoC values list in a threat feed comes from external security providers to identify potential threats. Occasionally, a specific IoC may incorrectly flag legitimate traffic on your network as malicious and generate false positive alerts or events, which can cause service disruptions.

If you experience a network disruption caused by false positive events/alerts, you can use the information to quickly resolve it.

  1. Find the alert: Search for the false positive event or alert in syslog/alerts in the Attack Log page.

  2. Identify the details: Go through the log or alert to get the necessary details, including the Matched Threat Feed (threat feed name) and the matching IOC value (IPv4/IPv6 endpoints, CIDRs, Domains, URLs, Domains, or File Hash) that blocked the traffic.

  3. Exclude the IoC value from the threat feed: Using that information, locate to the corresponding threat feed entry in the Feed Configuration page of the Manager, edit and deselect the specific IoC value, and save the changes. This action stops the Sensor from using that indicator for threat detection and response.

For example, if you observe multiple false-positive IoC alerts about a file that you do not want Sensors to block in your network environment, you need to first find the relevant alert entry in the Attack Log page. You can then obtain the details, such as Matched Threat Feed and matching file hash value(s) from the alert Summary and Details tabs.

HFP-1.png
HFP-2.png

Navigate to the Policy → <Admin Domain Name> → Threat Intelligence → Feed Configuration page and locate the corresponding thread feed entry from the list. Double-click it to edit, navigate to the IoC Values tab, deselect the matching file hashes, and click Save IoC Values button to save the changes.

HFP-3.png

To confirm, check if the excluded file hashes are listed on the Exclusions tab.

HFP-4.png