Investigate phishing emails

Prev Next

Trellix EDR analyzes emails reported as phishing to the Security Operations Center (SOC) and helps you perform the investigation.

It identifies and extracts email addresses, subject, body, attachments, metadata, and headers for better visualization. It also lets you view, analyze, and respond to phishing reports. Trellix EDR automatically analyzes IP addresses, fully qualified domain names (FQDNs), and files available on the analyzed email.

Important

This feature is only supported if your tenant is hosted in a United States data center.

  1. Log on to Trellix EDR as administrator.

  2. Click the configuration icon on the top-right corner to access the Configuration page.

  3. Click Manage integrations, then click + Add to add an integration.

  4. In the Name field, type the phishing email if you want to provide an email evidence of phishing and create an investigation.

    Note

    Phishing emails are supported only in unsigned and unencrypted .eml and .msg formats.

  5. Under the Action drop-down list, select Add Email Evidence, then click Save to add a new integration.