The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Grid Area

Prev Next

The following table explains the information available on the Enrichment Results home page, and indicates which columns are displayed by default.

Column Name

Description

Default Display

MD5

The MD5 hash of the file.

Yes

Status

The status of the enrichment request. Possible values include the following:

  • Requested: Queued for the Enricher Module.

  • Pending: Currently being processed.

  • Complete: Context API is complete without a detection conclusion.

  • Benign: Benign conclusion.

  • Malicious: Malicious conclusion.

  • Whitelisted: File is whitelisted.

Yes

Created

The date and time that the enrichment request was submitted.

Yes

SHA256

The SHA256 hash of the file.

Yes

SHA1

The SHA1 hash of the file.

Yes

Size

The size of the file.

Yes

MVX Verdict

The verdict received from MVX. Possible values include the following:

  • Benign

  • Malicious

  • Indeterminate: The MVX has no verdict on the file sample.

Yes

Trellix Verdict

The detection conclusion returned from the context API. Possible values include the following:

  • Benign

  • Malicious

  • Indeterminate: The context API has no verdict on the file sample.

Yes

Trellix Analysis Conclusion

The analysis conclusion from the context API.

Yes

Threat Names

The CSV list of malware names received from MVX.

Yes

Risk Level

The level of risk returned from the context API.

Yes

Type

The type returned from the context API.

Yes

Mime Type

The media type returned from the context API.

Yes

Alert URLs

The CSV list of the URLs to the alerts generated by MVX.

Yes

First Seen by FireEye

The date and time when the file was first encountered and reported by the context API.

Yes

Last Seen by FireEye

The date and time when the file was most recently encountered and reported by the context API.

Yes

Count

The number of times the file has been encountered and reported by the context API.

Yes

Labels

The CSV list of labels returned from the context API that are associated with the file.

Yes

Risk Summary

The risk summary returned from the context API for the file.

Yes

MVX Severity

The level of severity for the file as determined by MVX. Possible values are Critical, Major, Low, or Minor.

No

MVX Malicious Class Type

The class or type of malicious file to which the file belongs.

No

MVX Malicious Message

The malicious alert message returned from MVX.

No

MVX Type

The data source that provided the Enrichment; Malware Analysis, Local Virtual Execution, or Intelligent Virtual Execution - Cloud.

No

Trellix Description

The description returned from the context API.

No

Trellix Kill Chain Phases

The CSV list of kill chain phases returned from the context API.

No

Network Traffic Source Address

The source address of the network traffic returned from the context API.

No

Network Traffic Destination Address

The destination address of the network traffic returned from the context API.

No

Network Traffic Source Domains

The CSV list of network traffic source domains returned from the context API.

No

Network Traffic Destination Domains

The CSV list of network traffic destination domains returned from the context API.

No

Threat Actors

The CSV list of threat actors returned from the context API.

No

Threat Labels

The CSV list of threat labels returned from the context API.

No

Vendors

The CSV list of antivirus vendors returned from the context API.

No

Total Vendor Scanned

The total number of antivirus vendors scanned and returned from the context API.

No

Total Vendor Malicious

The total number of antivirus vendors reporting the file sample as malicious returned from the context API.

No

Vendor Confidence

The maximum antivirus vendor confidence returned from the context API.

No