The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Module overview

Prev Next

The Logon Tracker (LT) module is an Endpoint Security Innovation Architecture module designed to enable the investigation of lateral movement within Windows and Linux enterprise environments. The module improves the efficiency of investigating lateral movement by aggregating historical activity and monitoring new activity. This data is then presented in an interface designed for analyzing investigative leads (for example, a compromised account) and hunting suspicious activity (for example, RDP activity by privileged accounts).

Some of the key features that Logon Tracker provides are:

  • Visualization: Provides both a traditional grid view and a network graph visualization of logon data. The interface enables quick searching and pivoting on a variety of metadata including host name, account name, IP address, logon category (for example, RDP vs. Network vs. SSH), logon success, logon process, privilege level, group membership, and time of the day.

  • Data Reduction: Windows event logs are extremely verbose; only a small fraction of these logs are relevant in the context of lateral movement. Logon Tracker reduces the data set by filtering out unwanted events and by caching duplicate logon activity.

  • Historical Analysis: Analyzes existing Windows event logs and then monitors new activity. By including historical activity, Logon Tracker makes it possible to identify malicious activity that predates the Logon Tracker installation.

  • Enrichment: As logon events are collected on endpoints, they are also enriched to resolve IP addresses to host names and provide user account group membership and privilege level. This additional context enables the investigator to identify suspicious activity easily (for example: the use of privileged accounts.)

  • Alerting: Provides a rich editor for building custom rules to generate Endpoint Security alerts for suspicious lateral movement.