The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Network Security analysis

Prev Next

All network incidents are detected and categorized from the two phases.

The most common event types during the Infection Phase are:

  • Web Infection

  • Binary Analysis

  • Infection Match

A Web Infection is labeled an Exploit.Browser on the Network Security Alerts tab.

Binary Analysis generally occurs during the dropper phase. When a new Web binary is dropped into the victim machine, the analyzes it and profiles it as Malware.Binary on the Alerts pages.

A known malicious binary is displayed with its known name—one that has been seen before—not as Malware.Binary.

Infection Match refers to the process of identifying a URL pointing to the initial Web infection. A pattern match is performed from a full or partial URL to identify the infection.

An Infection Match that has been seen before is listed as Local.Infection. If it has never been seen before, it is identified as an Exploit.Browser.

During the Callback Phase, the Network Security appliance performs:

  • CnC Rule Matching

  • DNS Domain Name Matching

  • URLs and Non-HTTP callbacks

Trellix CnC rules are more specific and detailed than signature pattern matches. A signature is a binary pattern like 00101001101. ATrellix rule is a combination of URL, domain name, IP address, and other data.

For CnC Rule Matching, the Network Security appliance reviews CnC traffic over TCP, UDP, or HTTP. It also performs a DNS Match from DNS requests. When callbacks are collected by the Network Security appliance, a dynamic rule is created for each protocol to detect future callbacks that match the same criteria.

In the following example, callbacks are represented by their CnC destination or domain name, the country of destination, and by the number of attempts to contact the CnC server made by the malware callback.

NX_Alerts_Scap.png