Quickly drill down to threat details, file descriptions, and corresponding events for indicators of compromise (IOC) from external data sources, identified by cyber threat feeds.
On the Trellix ESM console, select → → → .
On the time frame list, select the time period for the view.
Filter by feed name or supported IOC data types.
For events and flows related to the selected IOC, perform any standard view action, including:
Create or append to a watchlist.
Create an alarm.
Execute a remote command.
Create an incident.
Look around or last look around.
Download the STIX xml file.
Select events or flows and click
to view the IOC details.In Details page you can view the IOC Description, Triggers (rules), Source Events, and Source Flows.