The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Investigation — Investigate an attack using Trellix EDR

Prev Next

Investigate the alert to determine if it's a false positive or malicious activity. For a quick overview, see the following workflow.

  1. Initial alert analysis:

    1. Review alert details in the EDR workspace > Monitoring dashboard.

    2. For specific details about the alert, review the Alerting dashboard:

      1. The name, data, and time of the impacted endpoint.

      2. The process name, which is, the command or script that triggered the alert.

      3. The technique ID, if available, which will correspond to a MITRE ATT&CK™ Matrix knowledge base article. See the section "Threat behavior" in Analyze threats.

      4. Review tactics and behaviors of adversaries that prompted EDRF to identify it as a suspicious indicator. See the section "Mapping of techniques observed and suspicious indicators" in Analyze threats.

      5. Use Trellix Wise to generate a Knowledge graph, which depicts the sequence of events and processes involved in the potential attack. See Search for historical data on a single endpoint.

    3. If the alert is still a potential threat, proceed to Step 2 Enrichment and deeper investigation.

  2. Enrichment and deeper investigation:

    1. Create an investigation for this potential threat using Generative AI.

    2. The operating system assigns a unique process ID (PID) to all processes. EDRF uses PID in its system monitoring, forensic investigation and threat remediation. Use a device search, which uses PID to follow all actions related to a specific threat, including network and DNS connections.

    3. Run a real-time search query to obtain the latest information from your endpoints.

    4. Use Historical Search on an endpoint to gather suspicious activity such as IOC hashes, trace time, and loaded DLLs over a defined timeframe.