Trellix Wise provides Generative Artificial Intelligence (AI) investigation capabilities to analyze threats through existing Trellix EDR workflows. You can run natural language queries to investigate threats, summarize threat data, and view breach information. You can visualize relationships between entities through a knowledge graph. Trellix Wise recommends remediation actions you can perform in the same window.
You can access Trellix Wise capabilities through the Monitoring page, Device Search, Historical Search, and Real Time Search workflows. Supported search workflows include natural language search in Historical Search and Real Time Search . Trellix Wise supports investigations in 11 languages.
Important
Trellix retires the previous Investigation feature on August 31, 2026. To continue investigating threats, use Trellix Wise capabilities in supported Trellix EDR workflows. Export or archive investigation data from the previous Investigation feature before August 31, 2026. After August 31, 2026, contact Trellix Support to retrieve historical investigation records.
Before you begin
The Trellix Wise add-on capability is enabled for your tenant at no additional cost. You do not need additional configuration to use Trellix Wise capabilities.
To enable Trellix Wise on your tenant:
Navigate to Menu → Configuration → Settings.
Select Wise Settings.
Turn on the Enable Trellix Wise toggle.
This enables Trellix Wise capabilities in Monitoring, Device Search, Historical Search, and Real Time Search.
Investigate threats using Trellix Wise
Follow a standardized investigative workflow to analyze and resolve threats using Trellix Wise.
Triage and analyze threats
Use Trellix Wise to analyze threats and provide context for your incident response team.
Navigate to the Monitoring dashboard and triage the threats.
Select a specific threat to analyze.
Select Ask Wise.
Select the Interactive or Dossier mode.
Trellix Wise provides a detailed natural language analysis of the threat.
Click the Copy button in Ask Wise panel to copy the analysis to a Jira or ServiceNow ticket.
Click the Draft an Email button in the Trellix Wise panel to directly add the analysis to an email.
This initiates the containment workflow and ensures the incident response team has immediate context.
Hunt across endpoints
When you identify a new threat, search across endpoints using natural language in Historical Search and Real Time Search.
Threat hunting in Historical Search
Use Historical Search to query past endpoint telemetry using natural language.
Select Menu > Historical Search.
Select Search with Wise.
Enter your threat hunting query in natural language into the search field.
Select a time period for the search.
Select the search icon to execute the query across stored endpoint data.
Filter or group grid columns, or select Export All to download up to 100,000 results.
Threat hunting in Real Time Search
Use Real Time Search to query active processes and current events on live managed endpoints.
Select Menu > Real Time Search.
Select Search with Wise.
Select a time period, then select Apply.
Enter your query in natural language into the search field.
Select the search icon to query live endpoints directly.
Review returned results, select Save Search to store the expression, or select Export All to export data.
Analyze behavior and root cause
When you investigate a potential credential theft threat, identify unusual memory access using Device Search. Trellix Wise reconstructs the attack path to visualize the initial execution and lateral movement.
Navigate to Device Search to view device events.
Select the specific events.
Select Ask Wise.
Select the Interactive or Dossier mode.
Trellix Wise provides a natural language analysis of the threat.
View the Knowledge Graph to analyze the attack path.
Share the Wise-generated details through email or an incident management tool such as Jira or ServiceNow.
This ensures that your incident response team shares an accurate understanding of the root cause.
Document incidents collaboratively
Use Trellix Wise to generate and share standardized summaries of event timelines for complex incidents. This provides context for stakeholders and streamlines the handover process between shifts.
Select Ask Wise in Monitoring or Device Search.
Select the Interactive or Dossier mode.
Trellix Wise provides a natural language analysis of the threat.
Click the Copy button in Ask Wise panel to copy the analysis to a Jira or ServiceNow ticket.
Perform remediation actions
When an investigation confirms a threat, use Ask Wise to expedite recovery.
After you analyze the incident in Monitoring or Device Search., select Ask Wise.
Select the Interactive or Dossier mode.
Select the Suggest some Recommended Actions interactive button.
Perform the recommended actions directly from the Ask Wise window.