Trellix Network Investigator is a security analytics solution that allows the analysis of alerts and network metadata gathered from all devices connected to it. Network Investigator (NI) can ingest alerts and collect Layer 7 metadata from other Trellix products, including Network Security (NX), Packet Capture (PX), and Endpoint Security (HX), and provides a high-level view of the network metadata gathered over customizable dashboards supporting multiple configurations. It thus enables users to have a metadata-based view of network activities and search indexed metadata from various network protocols, which allows them to zero down on threat information critical for performing further investigation.
Trellix IPS offers integration capability with Trellix NI using which it exports netflows and Layer 7 metadata from IPS Sensors, and alert data (including SmartVision attacks) from IPS Manager to NI, as per the configuration and filter parameters set by the user. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later send only SmartVision attack-related L7 metadata to NI. See Harnessing SmartVision attacks for effective threat detection and response for more information on SmartVision attacks.
The alert data, L7 metadata information, and net flow records exported by Trellix IPS are displayed on NI's Web UI which users can review and utilize further for the detection and analysis of network threats.
With the 11.1 Update 11 release, Trellix IPS integrated with Trellix NI supports IPv6 addresses for alert data, metadata, and netflow data for ICMP, UDP, and TCP protocols.