When Trellix EDR detects a threat, you can view several aspects of the threat to assess if it is malicious. You can create an investigation for the threat for further analysis, dismiss, or exclude a selected threat.
Log on to Trellix EDR as administrator.
Select Menu → Monitoring.
In the Threats by Ranking / Threats by Time pane, select a threat.
Tip
Use the Search filter in the Threats by Ranking / Threats by Time to find threats by name or ID.
To investigate, exclude, or dismiss the process on all affected devices, select an option from the Take Action menu in the Process Details pane.
Create an investigation — In the Create Investigation window, enter a name for the investigation and an optional comment, then click Create. The investigation is created and can be accessed from the Investigating dashboard. Click Go to investigation to open the newly created investigation.
Note
When an investigation is created based on a threat, that threat is removed from the threat list.
Exclude from threats — Excludes the selected process from the potential threat list. Once it is excluded, the threat, even if detected again, is not added back to the threat list.
Dismiss — Removes the potential threat from the threat list. If any activity with this threat is detected again, a new threat appears on the threat list as the historical information of that threat is not saved.