The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

STIX-based threat intelligence feed support for enhanced protection

Prev Next

Trellix IPS now enables you to leverage external threat intelligence data from third-party providers to strengthen your network defenses by offering an additional layer of security. You can import structured threat information, known as STIX (Structured Threat Information Expression) files, to the IPS Manager and Central Manager or configure the Manager to automatically retrieve these feeds from a TAXII server to proactively monitor and block malicious activity on your network.

When utilizing the TAXII server integration, the IPS Manager functions as a client, using a scheduler-driven pull mechanism to fetch threat indicators from the TAXII server's collection endpoints over HTTPS.

Trellix IPS can ingest threat data that follows the STIX 2.1 open standard, a common, JSON-based format for sharing threat intelligence. You can import several types of Indicators of Compromise (IoCs), such as the following:

  • IPv4 and IPv6 endpoints

  • IPv4 and IPv6 CIDRs

  • Domains

  • URLs

  • File hashes (MD5 and SHA-256)

Important

Trellix IPS currently supports only the malicious-activity as indicator type.

Once the threat feed configuration is saved and threat feed is imported (via manual file import or TAXII server fetch) into the IPS Manager, the IPS sensors to which the threat feed configuration is assigned will use IoC feeds to inspect and block the network traffic as per configuration. If any traffic matches an active IoC value from your feed -

  • For IPv4 and IPv6 endpoints and CIDRs, the Sensors block the traffic and forward alert details to the target syslog server configured for firewall access rule logging in the Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Logging → Firewall Access Logging page.

  • For domains, URLs and file hashes, the Sensors block the traffic (as per configuration in the chosen IPS/ advanced malware policy) and generate an alert in the Attack Log page. You can also configure these alerts to be sent to a syslog server for centralized monitoring.

Important

  • This feature is supported in IPS Manager, Central Manager, and Sensors running on software version 11.1 Update 11 or later.

  • Threat feeds created in the Central Manager are synchronized to the Manager. You must perform assignments exclusively from the Manager.

  • Supported Sensor models include NS9600 (standalone and stack), NS9500 (standalone and stack), NS7600, NS7500, NS3600, VM600, and VM5000, along with IPS-VM5000-SSL, IPS-VM600-SSL, and IPS-VM600-VSS-SSL Sensors for proxy-based SSL/TLS decryption.