The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Use case TQL queries

Prev Next

The following TQL queries are for general use cases.

Windows login and logoff events, to show Windows events, formatted in a table
class:ms_windows_event eventid:[4624,4634,4647,4648,4672,4688] has:username | table [hostname,username,eventid,service,severity,process,msg,accountdomain]
Windows events that could indicate lateral movement, commands executed with arguments
class=ms_windows_event has:args has:username | table [username,args] | groupby username
Failed connections to a single IP
application="unacknowledged connections" | groupby [dstipv4, connections] | sort > connections | table [connections, dstipv4, srcipv4]
SSH from the usual suspects
srccountrycode=[156,408,643] class:bro_ssh | table [eventtimeutc, srcipv4, dstipv4, srccountrycode, dstcountrycode] | sort < eventtime
SMTP traffic from an unauthorized host
!srcipv4=$server_smtp_ipv4s AND class:bro_conn AND dstport=25 | groupby [srcipv4]
Excessive SMTP traffic outbound
srcipv4:(application="outbound non-local traffic connection count anomalies" | table srcipv4) AND class:bro_conn AND dstport=25
Analytics logins from physical places that are not feasible in a time span
class=analytics application="non-vpn geo-infeasibility detector" | table [domain, username, description]
Excessive web or email traffic outbound
srcip:(application="outbound non-local trafov4fic connection count anomalies" | table srcipv4) AND dstport=[25,80] AND protcol=tcp| groupby [srcipv4, dstport] | table [srcipv4, dstport]
Excessive traffic inbound (for example, streaming and web traffic)
class:bro_files mimetype="application/octet-stream" total_bytes>104857600
HTTP transactions over non-standard ports with the usual suspects as destination
class=bro_http !dstport=[80,8080] AND dstcountrycode=[156,408,643] | table [srcipv4,dstcountrycode,domain,dstport,uri]
Excessive access to a malicious website from a single internal source
class:intel_hit program:bro_http
class:intel_hit program:bro_http AND !intelscore=low | groupby srcipv4 | table [srcipv4, intelmatchvalue, intelscore,domain,uri ] | sort  < srcipv4
Large files sent out to the usual suspects over non-standard ports
sentipbytes>250000 !dstport=[80,8080] dstcountrycode=[156,642,804,760,364,643,408] | groupby count | table [meta_ts, class, duration, srcipv4, srccountrycode, dstipv4, dstcountrycode, dstport, sentbytes, rcvdbytes] | sort > sentbytes
Compressed files to or from the usual suspects
class:bro_files mimetype:$compressed_mimes dstcountrycode=[156,642,804,760,364,643,408] | table [meta_ts,srcipv4,dstipv4,dstcountrycode,mimetype,seenbytes] | sort > dstipv4
Accessing a malicious website from multiple internal sources
class:intel_hit program:bro_http AND !intelscore=low | groupby domain | table [ intelmatchvalue, srcipv4, intelscore,domain,uri ] | sort < domain
Excessive connections to multiple hosts from a single host
class:bro_conn | groupby field = [srcipv4,dstipv4] threshold:10000
Excessive port blocking attempts from antivirus or other monitoring systems
class=cisco_asa action=deny srcipv4:["10.0.0.0/8","172.16.0.0/12","192.168.0.0/16"] AND !dstipv4:["10.0.0.0/8","172.16.0.0/12","192.168.0.0/16"] | groupby field = srcipv4 threshold:15
External Scanning
has:category category=scan::address_scan !srcipv4:["10.0.0.0/8","172.16.0.0/12","192.168.0.0/16"] application="unacknowledged connections"| table [eventtimeutc, msg, srccountry, srcdomain, srcipv4, srcisp]
Anomaly in user access and authentication baselines
class=analytics application="loginanomalies" | groupby username | table [username, description, eventtimeutc]
Anomaly in network baselines
application="outbound non-local traffic connection count anomalies" | groupby [srcipv4,count] | table [srcipv4, description]
Multiple infected hosts detected on a subnet
class=fireeye_nx msg=ips-event | groupby srcipv4 | table [srcipv4, srcport, dstipv4, dstport, eventlog]
srcipv4:(class=fireeye_nx msg=malware-callback OR msg=ips-event OR msg=malware-object) AND 
srcipv4=["144.155.0.0/16"] AND class=fireeye_nx| groupby msg | table [srcipv4, dstipv4, eventlog ]
Identified Tor Exit node match
has:context_tags context_tags:tor_exit | groupby [srcipv4, dstipv4]
Find internal servers using Google for DNS
protocol:udp dstport:53 dstipv4:["8.8.4.4","8.8.8.8"] srcisp:"private ip address lan" | groupby srcipv4
Example subsearch: Take all source IP addresses from intel hits and compare them to the bro_files log to see which ones downloaded an EXE file
srcipv4:(class:intel_hit) class:bro_files mimetype:"application/x-dosexec"
Find all inbound port 22 (SSH) connections
class:cisco_asa direction:inbound NOT (action:deny OR action:denied) dstport:22 |groupby [dstport,dstdomain]
Display list of logon attempts with good username but bad password by username and eventid
class:ms_windows_event eventid:[680,4776] errormessage:"0xC000006A" | groupby [username,eventid]
Changes to the Domain Admins group
Admins class:ms_windows_event eventid:4728 OR eventid:4729
Very broad potential exfil rule
class:bro_files mimetype:"application/x-rar"
class=bluecoat_http_proxy NOT uri=/.*chrome.*/ NOT uri="/msdownload/update/*" uri=/.*\.exe/ uri=/.*rar.*/ | groupby [uri,srcipv4,username,result]
class=bluecoat_http_proxy  filter="malicious_sources/malnets" | groupby domain
Names with dashes "-"
/.*host-name.*/
Histogram
program:kernel has(class) | histogram meta_ts hour
Palo Alto Networks (PAN) - Show large data transfers by service
class:paloalto_traffic sentbytes>11795 | groupby service
Regex example: Find all Snort alerts that contain "a network trojan"
class:snort AND rulecat=/.*(a network trojan).*/
Find foreign VPN logins in Cisco VPN logs
username:(class:cisco_vpn not srccountrycode:us NOT srcisp:"private ip address lan") AND program:"cscoacs_radius_accounting"