The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

View intelligence on the alert

Prev Next

Helix uses Trellix intelligence sources, as well as third party sources, to analyze events. Bringing this intelligence information into the event or alert provides more context, and can help you evaluate the event or alert more quickly. Using multiple sources of intelligence can reduce the likelihood of an event being classified as a false positive. You can view this detailed intelligence information on the Intel tab. The table shows each indicator of compromise (IOC) and any campaign or threat group associated with the event. When you select an IOC, a side panel displays any intelligence that Trellix Insights has on the IOC. The intelligence information is updated each time you select an IOC. Each IOC can have one or more campaigns associated with it.

Trellix Insights provides the latest global intelligence on the top campaigns that threat actors are using to target business sectors and organizations around the world. For more information, see the Insights Product Guide.

Trellix Insights provides the following information, if available, for each IOC and campaign.

Field

Description

Last seen

The date the IOC was last seen by Trellix.

Comment

More information on the IOC.

Determinism

How unique the IOC is to the campaign. The possible values are:

  • Very Unique — The IOC is unique and strongly associated with the campaign or threat group.

  • Unique — The IOC is used in multiple campaigns, but is unique to this threat group.

  • Partially Unique — The IOC has unique code segments or could use a vulnerability, but is not necessarily unique to this campaign or threat group.

  • Commodity — The IOC is part of the campaign or malware sample, but contains few unique elements. It is used by multiple campaigns and multiple threat groups.

  • Non-Deterministic — The IOC is commonly used but not malicious.

  • Unknown — There is not enough data to classify the uniqueness of the IOC.

Lethality

How lethal the IOC is. The possible values are:

  • Destructive — Definitely malicious and destructive.

  • Malicious — Definitely malicious, but less destructive

  • Malicious Enabler — A malicious tool used to drop a sample.

  • Probable Malicious - No sample is available, but the description of a sample analysis of the source suggests that it is probably malicious.

  • Dual Use — A non-malicious tool that is used maliciously.

  • Unconfirmed — No sample is available for analysis, or there is a lack of data sources to confirm the lethality.

Campaign

The name of the campaign.

Severity

How severe the campaign is. The possible values are: High, Medium, and Low.

Devices impacted

Which of your connected devices detected the IOC.

Geolocation

The countries where this campaign has been prevalent in the last 10 days.

Sector

The sectors where this campaign has been prevalent in the last 10 days.

Description

More context and information on the campaign. For example, information on the victims of the campaign, the threat actors carrying out the campaign, and the method of attack used.