Trellix provides indicators of compromise (IOCs) to help protect your environment. They are maintained by Trellix in the Dynamic Threat Intelligence (DTI) cloud. IOCs can also be generated from other Trellix appliances and supplied to the Endpoint Security (HX) appliance to aid in your investigations.
In addition, Endpoint Security (HX) can use your enterprise's own intelligence by helping your users to create, edit, and delete custom indicator of compromise rules. You create and edit indicator rules by adding and deleting individual conditions or by uploading lists of conditions:
Endpoint Security (HX) adds this intelligence to your list of indicator rules, along with indicator rules from other sources.
Important
Endpoint Security (HX) version 4.8 or later supports the creation of custom indicator rules for Linux conditions (network events only).