How Trellix appliance alerts become Endpoint Security (HX) alerts and Central Management badges

Prev Next

The Endpoint Security (HX) server generates endpoint alerts based on indicators of compromise (IOCs). It uses the following types of IOCs: Mandiant intelligence, Trellix appliance alerts, and custom intelligence. The Central Management appliance does not aggregate all of the Endpoint Security (HX) alerts, but only Endpoint Security (HX) alerts that are generated from a Trellix appliance IOC.

The following steps describe the process by which a Trellix appliance alert becomes an Endpoint Security (HX) alert and a Central Management badge:

  1. A Trellix appliance triggers an alert for a web infection, malware object, or malware callback.

  2. The Trellix appliance reports the alert to the Central Management appliance.

  3. The Central Management appliance determines if an IOC for the Endpoint Security (HX) server should be created and, if so, publishes it.

  4. The Endpoint Security (HX) server transforms the Central Management indicator into an Endpoint Security (HX) IOC and publishes it for the xAgents.

  5. The Endpoint Security (HX) agents search their hosts for any indicator of compromise. If a match is found, the agent reports back to the Endpoint Security (HX) server. The Endpoint Security (HX) server creates an alert, which is aggregated to the Central Management appliance if that alert was based upon an IOC from a managed appliance.

  6. The Central Management appliance correlates the Endpoint Security (HX) alert with the managed appliance alerts and creates badges for the appropriate alerts. Network Security alerts will have an endpoint compromised badge. Email Security — Server alerts will have a related endpoint badge.

Endpoint Security (HX) and Trellix appliance alert disparity

There is rarely a one-to-one relationship between Endpoint Security (HX) alerts and other Trellix appliance alerts.

Indicators that are passed to the Endpoint Security (HX) server may not produce alerts if the Trellix appliance blocks the malware download, if the combination of platform and application version do not expose the required vulnerability, or if the endpoint is no longer present in the network.

Network appliances evaluate possible infections within the network rather than actual infections. If a user accesses an infected website but the browser and system are not vulnerable to that infection, no infections are downloaded to their endpoint. But the network appliance still fully evaluates the infected site, running various browsers and versions to do so. It will likely generate multiple alerts for the infected site even though none of the infections occurred on the actual endpoint host and no Endpoint Security (HX) alerts have been generated.

Here are some other reasons why Endpoint Security (HX) and the other Trellix appliance alert counts differ:

  • Not all Trellix appliance alerts provide the kind of data from which an Endpoint Security (HX) indicator can be created.

  • Only alerts originating from Trellix appliance IOCs are aggregated to the Central Management appliance.

  • By default, only alerts that are classified as major severity alerts or higher are sent to the Endpoint Security (HX) server, resulting in only high-fidelity endpoint alerts.

Network Security and Endpoint Security (HX) alert matches

Network Security malware object and malware callback alerts are translated into Endpoint Security (HX) IOCs. An Endpoint Security (HX) alert is generated when an IOC condition is detected on an endpoint host. The Central Management appliance then aggregates the Endpoint Security (HX) alert and badges the original Network Security alert as endpoint compromised. It matches the endpoint host IP address with the Network Security alert source IP address and malware artifacts, confirming that evidence of the malware that triggered the Network Security alert was found on the endpoint host.

Email Security — Server and Endpoint Security (HX) alert matches

Email Security — Server malware object and malware callback alerts are translated into Endpoint Security (HX) IOCs. An Endpoint Security (HX) alert is generated when an IOC condition is detected on an endpoint host. The Central Management appliance then aggregates the Endpoint Security (HX) alert and badges the original Email Security — Server alert as a related endpoint. It matches endpoint host malware artifacts with the Email Security — Server alert malware artifacts, confirming that evidence of the malware that triggered the Email Security — Server alert was found on the endpoint host.

Email Security — Server alerts do not contain a source IP address that can be matched directly to the endpoint host IP address. The Central Management badge indicates the most probable source of origin of the compromise.