The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Access threat details

Prev Next

Quickly drill down to threat details, file descriptions, and corresponding events for indicators of compromise (IOC) from external data sources, identified by cyber threat feeds.

  1. On the Trellix ESM console, select + Add TabOpen ViewsDefault ViewsCyber Threat Indicators.

  2. On the time frame list, select the time period for the view.

  3. Filter by feed name or supported IOC data types.

  4. For events and flows related to the selected IOC, perform any standard view action, including:

    • Create or append to a watchlist.

    • Create an alarm.

    • Execute a remote command.

    • Create an incident.

    • Look around or last look around.

  5. Download the STIX xml file.

  6. Select events or flows and click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png to view the IOC details.

    In Details page you can view the IOC Description, Triggers (rules), Source Events, and Source Flows.