The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sample CSV notifications per event type

Prev Next

Sample CSV notifications are shown for various event types. The definitions for each of the <extension> field keys are provided in CSV extension field key=value pair definitions.

Note

The product names in CSV notifications are ‘MPS’ (for Network Security), ‘eMPS’ (for Email Security — Server Edition) ‘fMPS’ (for File Protect), ‘MAS’ (for Malware Analysis), 'HX' (for Endpoint Security) and ‘CMS’ (for Central Management).

domain-match (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:DM:domain-match,osinfo=,sev=minr,malware_
type=,alertid=85,app=,spt=1070,locations=,smac=6a:c0:02:9a:9b:7d,header=,cnchost=fgetcareer.
com,alertType=domain-match,shost=,dst=,original_name=,application=,sid=80461038,malwarenote=,
sha256=,objurl=,mwurl=,profile=,dmac=00:50:56:e5:3f:c5,product=Web
MPS,sname=Trojan.Ramnit.SNK.DNS,fileHash=,dvchost=abc.mrl.trellix.com,occurred=2020-10-
16T14:36:16Z,release=9.0.2.924861,dpt=,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id=85,cncport=53,src=xxx.xxx.xxx.xxx,sha1=,sha512=,dvc=10.5.6.126,channel=,anomaly=,action=notified,os=,stype=b
lacklist, .

domain-match (Network Security on Central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:DM:domain-match,osinfo=,sev=minr,malware_
type=,alertid=70200,app=,spt=1062,locations=,smac=d6:96:0a:84:24:15,header=,cnchost=fgetcareer.
com,alertType=domain-match,shost=,dst=,original_name=,application=,sid=80461038,malwarenote=,
objurl=,mwurl=,profile=,dmac=00:50:56:e5:3f:c5,product=MPS,sname=Trojan.Ramnit.SNK.DNS,fileHash=,dvchost=
xxxx,occurred=2020-06-28T09:47:43Z,release=wMPS (wMPS) 9.0.0.916432,link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?ev_
id=70200,cncport=53,src=xxx.xxx.xxx.xxx,dpt=,anomaly=,dvc=xx.x.x.xxx,channel=,action=notified,os=,stype=blackli
st,

infection-match (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:IM:infection-match,osinfo=,sev=minr,malware_
type=,alertid=84,app=,spt=1058,locations=,smac=6a:c0:02:9a:9b:7d,header=,cnchost=xxx.xxx.xxx.xxx,alertType=infe
ction-match,shost=,dst=xxx.xxx.xxx.xxx,original_name=,application=,sid=84400123,malwarenote=,
sha256=,objurl=,mwurl=,profile=,dmac=00:50:56:e5:3f:c5,product=Web
MPS,sname=Worm.Ramnit,fileHash=,dvchost=abc.mrl.trellix.com,occurred=2020-10-
16T14:36:12Z,release=9.0.2.924861,dpt=80,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id=84,cncport=80,src=xxx.xxx.xxx.xxx,sha1=,sha512=,dvc=xx.x.x.xxx,channel=GET http://yy8311.com/?/goods_
list/14_25_0 HTTP/1.1::~~Host: yy8311.com::~~../..7^{xd_.4=.k....]..}xFs...`k..z{.\y.[..O..d.G....p7y.{g
xa%k._.....M?~..}.ox..cx\{|Z._h~x8?t|m_O.d0\.GA.._{O=...Q}G/UG.+;..po\G/v^..p..u..p..np;]=|....={~/yN..V|x|.[_
\S/]c^.]/|ic}[........6 7Z_`c8.]{r=;_....u7.=.~.o.5W62>4w_s>X)c..Q>z.k^%O?EO].)..-a4.q8C.[WO{gwx*;?~?{{?][p^{gg
{~_y.....|...}...o.ka..k./iz.....<gk?.?q...W::....UnI....D.1..L3.1fxL~~y4 m.o..::....[W.}{_}+w...._
yk9~].....<.N?.8..8^...}]:96h.~.."4..._~U.y/?.v<6X{..l...?c......QW?+<zzyn?>.x,O=...>7?.'>xy_y{t.?>.}W>%KY-
<.G|.....iiU...... 94pnPZgs[y..N!=.b9.=47%u^.g+G(k..RGe>e?CNGc\B2O2mmgO};..e.[^s
(.jbM.OZV,anomaly=,action=notified,os=,stype=bot-command, .

infection-match (Network Security on Central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:IM:infection-match,osinfo=,sev=minr,malware_
type=,alertid=70184,app=,spt=1165,locations=US/TN/Johnson
City,smac=92:73:75:00:00:35,header=,cnchost=xxx.xxx.xxx.xx,alertType=infection-match,shost=xxx-xxx-xxxxxx.
rev.home.ne.jp,dst=xxx.xxx.xxx.xx,original_name=,application=,sid=600144,malwarenote=,
objurl=,mwurl=,profile=,dmac=00:19:d1:fd:a2:52,product=MPS,sname=Local.Infection,fileHash=,dvchost=xxxx,o
ccurred=2020-06-28T09:02:20Z,release=wMPS (wMPS) 9.0.0.916432,link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?ev_id=70184,cncport=80,src=xxx.xxx.xxx.xxx,dpt=80,anomaly=,dvc=xx.x.x.xxx,channel=GET
/014.exe HTTP/1.1::~~Accept: */*::~~Accept-Encoding: gzip, deflate::~~User-Agent: Mozilla/4.0 (compatible; MSIE
6.0; Windows NT 5.1; SV1)::~~Host: exe.xinniankl.com::~~Connection: Keep-
Alive::~~::~~,action=notified,os=,stype=bot-command,

malware-callback (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:MC:malware-callback,osinfo=,sev=crit,malware_
type=,alertid=88,app=,spt=49193,locations=HK/Kwun
Tong,smac=00:0c:29:75:37:4a,header=,cnchost=xx.xxx.xxx.xxx,alertType=malwarecallback,
shost=,dst=xx.xxx.xxx.xxx,original_name=,application=,sid=86112670,malwarenote=,
sha256=,objurl=,mwurl=,profile=,dmac=00:50:56:fe:a1:97,product=Web
MPS,sname=Trojan.Gootkit,fileHash=,dvchost=abc.mrl.trellix.com,occurred=2020-10-
16T14:36:29Z,release=9.0.2.924861,dpt=443,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id=88,cncport=443,src=xx.xxx.xxx.xxx,sha1=,sha512=,dvc=xx.x.x.xxx,channel=...,anomaly=,action=notified,os=,styp
e=bot-command, .

malware-callback (Network Security on Central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:MC:malware-callback,osinfo=,sev=crit,malware_
type=,alertid=70252,app=,spt=55689,locations=,smac=00:0c:29:ec:df:a4,header=,cnchost=xxx.xx.x.xx,alertType=malw
are-callback,shost=,dst=xxx.xx.x.xx,original_name=,application=,sid=33351211,malwarenote=,
objurl=,mwurl=,profile=,dmac=00:50:56:be:42:a6,product=MPS,sname=Trojan.APT.PingBed,fileHash=,dvchost=xxx
x,occurred=2020-06-29T07:00:34Z,release=wMPS (wMPS) 9.0.0.916248,link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?ev_id=70252,cncport=8080,src=xxx.xx.x.xx,dpt=8080,anomaly=,dvc=xx.x.x.xxx,channel=GET
http://colville.com/Gallery/Winterfest/2.jpg HTTP/1.1::~~User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows
NT 5.1; Trident/4.0; #1atEW5tuNDl0kt579c9.BMWUS)::~~Host: Colville.com::~~Pragma: nocache::~~::~~,
action=notified,os=,stype=bot-command

malware-object (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:MO:malware-object,osinfo=Microsoft Windows7 64-bit x.x sp1 17.0114;Microsoft
WindowsXP 32-bit 5.1 sp3 17.0114,sev=majr,malware_
type=exe,alertid=32,app=,spt=3926,locations=,smac=00:50:8b:08:b8:f6,header=GET /images/miscexes/
0d043e3acbc3af58970d3365b6f91d29.exe HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Referer: http://xxx.xxx.x.xxx/images/misc-exes/ Accept-Language: en-us Accept-Encoding: gzip, deflate User-
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; (R1 1.3); InfoPath.2) Host: xxx.xxx.x.xxx
Connection: Keep-Alive HTTP/1.1 200 OK Date: Thu, 27 Nov 2008 07:35:32 GMT Server: Apache/2.2.3 (Fedora) Last-
Modified: Fri, 09 May 2008 10:21:38 GMT ETag: "4f83f6-15cc2-902f5080" Accept-Ranges: bytes Content-Length:
89282 Connection: close Content-Type: application/octet-stream,cnchost=wa3d.no-ip.biz,alertType=malwareobject,
shost=,dst=xxx.xxx.x.xxx,original_name=0d043e3acbc3af58970d3365b6f91d29.exe,application=Windows
Explorer,sid=,malwarenote=,
sha256=9a8724dfb4ae1f044a28be30ff3885b7558d1ae00664308ecb11f7164a7a3ddf,objurl=,mwurl=192.168.2.171/image
s/misc-exes/0d043e3acbc3af58970d3365b6f91d29.exe,profile=winxp-sp3,dmac=00:02:b3:a1:87:14,product=Web
MPS,sname=Win.Trojan.Bifrose-194;fe_ml_heuristic;Malware.Binary.exe,fileHash=0d043e3acbc3af58970d

malware-object (Network Security on Central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:MO:malware-object,osinfo=,sev=majr,malware_
type=exe,alertid=23049,app=,spt=1165,locations=,smac=92:73:75:00:00:35,header=GET /014.exe HTTP/1.1 Accept: */*
Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) Host:
exe.xinniankl.com Connection: Keep-Alive HTTP/1.0 200 OK Content-Length: 23717 Content-Type: application/octet-
stream Last-Modified: Mon, 25 Feb 2008 15:47:02 GMT Accept-Ranges: bytes ETag: "e0e6f3a9c577c81:470" Server:
Microsoft-IIS/6.0 Date: Sun, 23 Mar 2008 03:27:10 GMT Age: 44649 X-Cache: HIT from gateway.palmchip.com XCache-
Lookup: HIT from gateway.palmchip.com:3128 Via: 1.0 gateway.palmchip.com:3128 (squid/2.6.STABLE16)
Connection: keep-alive,cnchost=,alertType=malware-object,shost=119-168-188-
108.rev.home.ne.jp,dst=xxx.xxx.xxx.xx,original_name=014.exe,application=,sid=,malwarenote=,
objurl=,mwurl=exe.xinniankl.com/014.exe,profile=,dmac=00:19:d1:fd:a2:52,product=MPS,sname=Heuristic.Backd
oor.20,fileHash=bfaf373042d10517fdc0fe713bbeb093,dvchost=xxxx,occurred=2020-06-28T08:54:56Z,release=wMPS (wMPS)
9.0.0.916432,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ma_
id=23049,cncport=,src=xxx.xxx.xxx.xxx,dpt=80,anomaly=,dvc=xx.x.x.xxx,channel=,action=notified,os=,stype=knownmd5sum,

malware-object (File Protect)

CSV:0:Trellix:File MPS:9.0.0.916210:MO:malware-object,osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0112;Microsoft Windows7 64-bit 6.1 sp1 17.0112,sev=majr,malware_
type=exe,alertid=92,locations=,header=,cnchost=xx.xx.xx.xx,alertType=malware-object,repository=liveurl,
original_name=/data/ma/notify/Malware_Sample135,application=Windows Explorer,run_end=2020-06-
26T17:06:53Z,sid=86107514;86115447;89080514;86117644,malware-note=,anomaly=98304,mwurl=/data/ma/notify/Malware_
Sample135,profile=win7x64-sp1,parent_maid=,product=File MPS,sname=fe_ml_
heuristic;Trojan.Sality,fileHash=434da9ab51c3f9e70b7611bd70cc9e52,dvchost=xx-xxxxx.
eng.trellix.com,occurred=2020-06-26T17:02:43Z,link=https://xx.xxx.xx.xxx/fmps/fanalysis?ma_id=92&lms_
iden=0CC47AA8FFA6,cncport=7455,url_domain=,download_end=2020-06-
26T17:06:52Z,dvc=xx.xxx.xx.xxx,username=,channel=,release=9.0.0.916210,malware_scan_id=1,stype=malwareguard;
vm-bot-command

malware-object (Malware Analysis)

CSV:0:Trellix:MAS:9.0.0.916210:MO:malware-object,osinfo=Microsoft Windows10 64-bit 10.0 base
17.0112,sev=majr,malware_type=doc,al ertid=15741,locations=,header=,cnchost=,alertType=malware-object,original_
name=/data/ma/share/source_mas/4fdd859854b5d4b54a2effe6608aeb7e,application=MS Word 2013 SP1,run_end=2020-06-
23T07:38:00Z,si d=111,malware-note=,anomaly=512,mwurl=/data/ma/share/source_
mas/4fdd859854b5d4b54a2effe6608aeb7e,profile=win10x64,parent_maid=,product=MAS,sname=Doc.Trojan.Xaler-1;FE_
Macro_keimeno_Doc,fileHash=4fdd 859854b5d4b54a2effe6608aeb7e,dvchost=xx-xxx-xx.eng.trellix.com,occurred=2020-
06-22T17:07:27Z,link=https://xx-xxx-xx.eng.trellix.com/malware_analysis/analyses?maid=15741,cncport=,url_
domain=,download _end=2020-06-
23T07:37:59Z,dvc=xxx.xx.xxx.xx,username=unattended,channel=,release=9.0.0.916210,stype=av-match;yara,

malware-object (Email Security)

CSV:0:Trellix:Email MPS:9.0.2.925255:MO:malware-object,osinfo=Microsoft Windows7 64-bit 6.1 sp1
17.0114,sev=majr,malware_
type=exe,alertid=20,locations=,header=,cnchost=xezlifewvupazah.ws,protocol=,subject=mal sample ::
original,alertType=malware-object,date=Thu, 22 Oct 2020 12:30:16 +0500,smtp-to=samples@tesoro.com,original_
name=......... ............... ............... ............ .........,application=Windows Explorer,run_
end=2020-10-22T07:33:36Z,last-malware=Trojan.Expiro,sid=33351836;86105968,malwarenote=,
sha256=83920de959a29be45ff40a3f513f7ec94ad21433e009a3f9e36dea44a8d42b45,sha512=601a9acb9417210612be55d282
e6eb672a5a6d66890f7decb432184e655248a5236d96a89f34e23ede57cd5864e040e2b2a0d88cff62375ccc95ea5822440047,mwurl
=......... ............... ............... ............ .........,profile=win7x64-sp1m,product=Email
MPS,sname=fe_ml_heuristic;Trojan.Expiro,fileHash=ebe52c916b26694796abef44b154e58e,dvchost=abc-
123.mrl.trellix.com,occurred=2020-10-22T07:30:24Z,smtp-mail-from=sample@tesoro.com,smtp-cc=,link=https://abc-
123.mrl.trellix.com/emps/eanalysis?e_id=12&type=attch,cncport=80,url_
domain=,sha1=be89a185d43bd7e003b33d46e59d1671c323427c,anomaly=99329,download_end=2020-10-
22T07:33:35Z,dvc=10.5.6.115,username=,channel=POST xezlifewvupazah.ws HTTP/1.1::~~User-Agent: Mozilla/4.0
(compatible; msie 40; NT6.1.7601-7C783FD6.ENU.00371-222-1977552-33559_1B41C8; .NET CLR
00000000/00000000)::~~::~~, E.......@...

web-infection (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:WI:web-infection,osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0114,sev=majr,malware_type=,alertid=4079,app=InternetExplorer
8.0,spt=1058,locations=,smac=6a:c0:02:9a:9b:7d,header=,cnchost=fget-career.com,alertType=webinfection,
shost=,dst=xxx.xxx.xxx.xxx,original_name=,application=,sid=86115851,malwarenote=,
sha256=,objurl=yy8311.com/?/goods_list/14_25_0,mwurl=,profile=winxp-sp3,dmac=,product=Web
MPS,sname=HTML.Infector.Ramnit;Trojan.Ramnit,fileHash=,dvchost=abc.mrl.trellix.com,occurred=2020-10-
16T14:41:43Z,release=9.0.2.924861,dpt=80,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?inc_
id=4079,cncport=443,src=xxx.xxx.xxx.xxx,sha1=,sha512=,dvc=xx.x.x.xxx,channel=\000\377\001\000\000\000,anomaly=9
8305,action=notified,os=Microsoft WindowsXP 32-bit 5.1 sp3 17.0114,stype=trellix-content;vm-bot-command, .

web-infection (Network Security on central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:WI:web-infection,osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0113,sev=majr,malware_type=,alertid=151,app=InternetExplorer
8.0,spt=1057,locations=,smac=d6:96:0a:84:24:15,header=,cnchost=xisock.com,alertType=web-infection,shost=xx-xxxxx-
xx.dyn.actaccess.net,dst=xx.xx.xxx.xxx,original_name=,application=,sid=86115851;86114877;86114876,malwarenote=,
objurl=yipinlawyer.com/,mwurl=,profile=winxp-
sp3m,dmac=,product=MPS,sname=Exploit.Browser;Trojan.Virut.DNS;Trojan.Ramnit,fileHash=,dvchost=xxxx,occurred=202
0-06-29T05:47:41Z,release=wMPS (wMPS) 9.0.0.916248,link=https://abc.mrl.trellix.com/event_stream/events_for_
bot?inc_
id=151,cncport=443,src=xx.xxx.xx.xx,dpt=80,anomaly=,dvc=xx.x.x.xxx,channel=,action=notified,os=Microsoft
WindowsXP 32-bit 5.1 sp3 17.0113,stype=vm-bot-command,

ips-event (Network Security)

CSV:0:Trellix:Web MPS:9.0.0.916432:IE:ips-event,id=12,occurred=2020-06-
26T13:30:17Z,src=xxx.xx.x.xx,spt=80,smac=00:17:a4:aa:f4:93,dst=xxx.xx.x.xxx,dpt=1043,dmac=00:0c:29:b2:fb:4f,sev
=crit,sigId=85302399,sigrevision=12,matchcount=1,signame=Microsoft Internet Explorer XML Processing Memory
Corruption,cve_id=,action_taken=notified,attack_mode=client,url=https://abc.mrl.trellix.com/notification_
url/ips_events?ev_id=12,mvx_status=N/A

ips-event (Network Security on Central Management)

CSV:0:Trellix:CMS:9.0.0.916210:IE:ips-event,id=15,occurred=2020-06-
29T08:36:01Z,src=xxx.xx.x.x,spt=80,smac=00:1b:78:75:79:68,dst=172.16.8.44,dpt=33501,dmac=00:0c:29:5e:e3:6c,sev=
crit,sigId=85311119,sigrevision=8,matchcount=1,signame=Potential Heap Spray Memory Allocation,cve_id=,action_
taken=notified,attack_mode=client,url=https://abc.mrl.trellix.com/notification_url/ips_events?ev_id=15,mvx_
status=N/A

SmartVision (Network Security)

CSV:0:Trellix:Web MPS:9.0.0.916432:WA:smartvisionevent,
id=1,sigId=91500000,sigrevision=5,eventCount=5,occured=2020-06-26
12:43:45,sev=5,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,vlan=0,name=Suspicious Remote Scheduled Task
Activity,type=T1053 / Remote Execution,description=Suspicious Remote Scheduled Task
Activity,url=https://abc.mrl.trellix.com/notification_url?uuid\=20281250-7c27-4cce-a410-2f04e1002c6e,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=1,alertId=1,sigId=0,occured=2020-06-
26T12:42:07Z,name=SMB Create Request: Delete file in Windows temp
direcory,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"user": "DomainAdmin",
"domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=2,alertId=1,sigId=0,occured=2020-06-
26T12:42:06Z,name=SMB Create Request: File in Windows temp
direcory,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=3,alertId=1,sigId=0,occured=2020-06-
26T12:42:07Z,name=ATSVC Start Job,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails=
{"user": "DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=4,alertId=1,sigId=0,occured=2020-06-
26T12:42:07Z,name=ATSVC Delete Job,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails=
{"user": "DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=5,alertId=1,sigId=0,occured=2020-06-
26T12:42:06Z,name=ATSVC Add Job: cmd.exe /C with
redirect,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA,

SmartVision (Network Security on Central Management)

CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=11,alertId=7,sigId=0,occured=2020-06-
29T08:13:35Z,name=SMB Create Request: Delete file in Windows temp
direcory,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"user": "DomainAdmin",
"domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=13,alertId=7,sigId=0,occured=2020-06-
29T08:13:34Z,name=SMB Create Request: File in Windows temp
direcory,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA,
CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=12,alertId=7,sigId=0,occured=2020-06-
29T08:13:34Z,name=ATSVC Add Job: cmd.exe /C with
redirect,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA,
CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=15,alertId=7,sigId=0,occured=2020-06-
29T08:13:35Z,name=ATSVC Delete Job,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails=
{"user": "DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=14,alertId=7,sigId=0,occured=2020-06-
29T08:13:35Z,name=ATSVC Start Job,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails=
{"user": "DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:CMS:9.0.0.916210:WA:smartvisionevent,
id=7,sigId=91500000,sigrevision=5,eventCount=5,occured=2020-06-29
13:14:34,sev=5,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,vlan=0,name=Suspicious Remote Scheduled Task
Activity,type=T1053 / Remote Execution,description=Suspicious Remote Scheduled Task
Activity,url=https://abc.mrl.trellix.com/notification_url?uuid\=5985dbd8-5066-4e04-b560-3f05c93506d6, .