Helix uses Trellix intelligence sources, as well as third party sources, to analyze events. Bringing this intelligence information into the event or alert provides more context, and can help you evaluate the event or alert more quickly. Using multiple sources of intelligence can reduce the likelihood of an event being classified as a false positive. You can view this detailed intelligence information on the Intel tab. The table shows each indicator of compromise (IOC) and any campaign or threat group associated with the event. When you select an IOC, a side panel displays any intelligence that Trellix Insights has on the IOC. The intelligence information is updated each time you select an IOC. Each IOC can have one or more campaigns associated with it.
Trellix Insights provides the latest global intelligence on the top campaigns that threat actors are using to target business sectors and organizations around the world. For more information, see the Insights Product Guide.
Trellix Insights provides the following information, if available, for each IOC and campaign.
Field | Description |
|---|---|
Last seen | The date the IOC was last seen by Trellix. |
Comment | More information on the IOC. |
Determinism | How unique the IOC is to the campaign. The possible values are:
|
Lethality | How lethal the IOC is. The possible values are:
|
Campaign | The name of the campaign. |
Severity | How severe the campaign is. The possible values are: High, Medium, and Low. |
Devices impacted | Which of your connected devices detected the IOC. |
Geolocation | The countries where this campaign has been prevalent in the last 10 days. |
Sector | The sectors where this campaign has been prevalent in the last 10 days. |
Description | More context and information on the campaign. For example, information on the victims of the campaign, the threat actors carrying out the campaign, and the method of attack used. |