You can retrieve indicators of compromise (IOC) from remote sources and quickly access related IOC activity in your environment.
Cyber threat management enables you to set up automatic feeds that generate watchlists, alarms, and reports, giving you visibility to actionable data. For example, you can set up a feed that automatically adds suspicious IP addresses to watchlists to monitor future traffic. That feed can generate and send reports indicating past activity. Use → or on the Trellix ESM console use → → → to drill down quickly to specific events and activity in your environment.
Supported IOC types
When you add a manual upload cyber threat feed, Trellix ESM sends the Structured Threat Information eXpression (STIX) file to the Indicator of Compromise (IOC) engine to be processed. If the file doesn't contain an IOC that is normalized for Trellix ESM, you receive an error message.
Indicator types normalized for Trellix ESM
Indicator type | Watchlist type |
|---|---|
Email Address | To, From, Bcc, Cc, Mail_ID, Recipient_ID |
File Name, File Path | File_Path, Filename, Destination_Filename, Destination_Directory, Directory |
(Flows) IPv4, IPv6 | IPAddress, Source IP, Destination IP |
(Flows) MAC Address | MacAddress, Source MAC, Destination MAC |
Fully qualified domain name, Host Name, Domain Name | Host, Destination_Hostname, External_Hostname, Domain, Web_Domain |
IPv4, IPv6 | IPAddress, Source IP, Destination IP, Attacker_IP, Grid_Master_IP, Device_IP, Victim_IP |
MAC Address | MacAddress, Source MAC, Destination MAC |
MD5 Hash | File_Hash, Parent_File_Hash |
SHA1 Hash | SHA1 |
Subject | Subject |
URL | URL |
User name | Source User, Destination User, User_Nickname |
Windows Registry Key | Registry_Key, Registry.Key (Registry subtype) |
Windows Registry Value | Registry_Value, Registry.Value (Registry subtype) |
.png)