The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Perform GTI Forensics

Prev Next

GTI forensics connects to the GTI cloud and extracts the forensics information for the endpoint. It displays the threat details for the endpoint.

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.

  2. Select the alert whose IP address to which you want to perform forensics.

  3. Click Other Actions, and select Perform GTI Forensics. Click the endpoint IP for which you want to perform forensics.

    The Threat Intelligence forensics page opens in your browser with information about the endpoint.