The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Key features

Prev Next

NDR key features focus on enhancing the analyst experience, improving visibility, and expanding detection and integration capabilities:

  • Enhanced Alert Analysis: Improved workflows with new alert and user views, synchronized filtering across dashboards, and enhanced analyst springboards for prioritized threat investigation. Features risk-based severity scoring with MITRE, Tenable, and ePO integration, plus customizable severity badges.

  • Improved Asset display: A new Assets List view with persistent filters, CSV download, and integration with ePO and Tenable for enriched asset data. The Asset Details view now includes dedicated panels for events, alerts, and conversation graphs.

  • Comprehensive Integrations: A new Integration Hub manages enhanced SIEM (Splunk), Tenable Security Center, and on-premises ePO integrations.

  • Attack Path Discovery: Provides detailed insights into attack paths for specific assets (Enterprise License only).

  • Selective Packet Capture: Enables capturing network traffic around suspicious assets for closer investigations.

  • Expanded Threat Detection: New capabilities include detecting communication with malicious domains, DNS/ICMP tunneling, phishing, SSL anomalies, Tor activity, and suspicious URLs.

  • AI-Powered Alert Investigation: Integrates with Trellix WISE (GenAI) for conversational AI-assisted alert investigations, reducing false positives.

  • GTI Integration: Queries Global Threat Intelligence (GTI) for URL reputation to enhance detection capabilities.

  • DNS Tunneling Detection: CLI-configurable DNS tunneling exploit detection to monitor for malicious DNS activity.

  • Product Editions: Now available in Essentials, Core, and Enterprise editions.