The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Cyber threat

Prev Next

You can retrieve indicators of compromise (IOC) from remote sources and quickly access related IOC activity in your environment.

Cyber threat management enables you to set up automatic feeds that generate watchlists, alarms, and reports, giving you visibility to actionable data. For example, you can set up a feed that automatically adds suspicious IP addresses to watchlists to monitor future traffic. That feed can generate and send reports indicating past activity. Use GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.pngCyber Threat Indicators or on the Trellix ESM console use + Add TabOpen ViewsDefault ViewsCyber Threat Indicators to drill down quickly to specific events and activity in your environment.

Supported IOC types

When you add a manual upload cyber threat feed, Trellix ESM sends the Structured Threat Information eXpression (STIX) file to the Indicator of Compromise (IOC) engine to be processed. If the file doesn't contain an IOC that is normalized for Trellix ESM, you receive an error message.

Indicator types normalized for Trellix ESM

Indicator type

Watchlist type

Email Address

To, From, Bcc, Cc, Mail_ID, Recipient_ID

File Name, File Path

File_Path, Filename, Destination_Filename, Destination_Directory, Directory

(Flows) IPv4, IPv6

IPAddress, Source IP, Destination IP

(Flows) MAC Address

MacAddress, Source MAC, Destination MAC

Fully qualified domain name, Host Name, Domain Name

Host, Destination_Hostname, External_Hostname, Domain, Web_Domain

IPv4, IPv6

IPAddress, Source IP, Destination IP, Attacker_IP, Grid_Master_IP, Device_IP, Victim_IP

MAC Address

MacAddress, Source MAC, Destination MAC

MD5 Hash

File_Hash, Parent_File_Hash

SHA1 Hash

SHA1

Subject

Subject

URL

URL

User name

Source User, Destination User, User_Nickname

Windows Registry Key

Registry_Key, Registry.Key (Registry subtype)

Windows Registry Value

Registry_Value, Registry.Value (Registry subtype)