The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Navigating the Story Graph

Prev Next

The Story Graph in the Threat Event Log provides a visual representation of file-based and fileless-based ATP threat detections. You can examine the context of threats by reviewing the details of events leading up to a detection.

For ATP to generate a Story Graph, you must enable these options in the Adaptive Threat Protection Options policy:

  • Adaptive Threat Protection

  • One of these options:

    • Trigger Dynamic Application Containment when reputation threshold reaches

    • Block when reputation threshold reaches

    • Clean when reputation threshold reaches

    The reputation threshold specified must also match the reputation of the detected event.

The Story Graph helps you answer these questions:

  • What was executed?

  • Why does ATP think it's malicious?

  • Where did the threat come from?

  • When in the attack chain did ATP stop the threat?

To view the graph for a particular threat event, open the Threat Event Log, select an event, and scroll down to the Story Graph (Trace Summary) section.

Identifying events

Icons on the Story Graph represent the type of event being traced.

  • Processes — gear icons GUID-55AC5083-4458-45E7-9E1C-7F96DED37F63-low.png

  • Files — document icons GUID-11561E2E-AC1E-48F7-8DE8-9832E5B5AD2F-low.png

  • Temp files — microSD card icons GUID-51A130B0-4C3C-4F2E-9F58-E0B6CA5CEC52-low.png

Temp files represent an event that occurred in memory. AMSI detects these types of events.

Event colors indicate the reputation score. The Color Legend shows the reputation score range associated with each color.

Investigating events

The Story Graph is made up of several parts where you can view detection data.

GUID-955D596A-99AB-416D-AD54-3FBC9C1F0DEC-low.png
  1. View the process name of each actor involved in the detection.

  2. Follow the events in the graph, from left to right, to see what led to the detection.

    A blue border appears around the selected event. The last event is selected by default and is where the detection occurred.

  3. Investigate the suspicious activity by examining the data for each event in the graph.

    Click any event to open the Event Details window. The event data provides context that enables you to see why ATP deems the event malicious. For example, you can see the changes in reputation score and command-line parameters from event to event and the primary trigger that started the malicious activity.

  4. Review details about the process that started the event.

    The Actor section doesn't appear for events where the target and the actor are the same, for example, if the process was already running.

Additional Story Graph data and any remediation details are available on the client system. ATP retains Story Graph data and remediation details for up to 90 days or 100 events. For more information, see KB90859.

Event data

Event Details window

Item

Definition

Target Name

Identifies the name of the file or process being operated on.

Reputation

Indicates the reputation given by the reputation provider.

Reputation Score

Indicates the reputation score.

PID

Indicates a unique identifier for the process.

Action Taken

Describes the security action taken on the detected event (the last event in the graph).

SHA-256

Indicates the SHA-256 hash (64-digit hexadecimal number) of the file.

Tip

Use the SHA-256 hash for file inspections with VirusTotal. To copy the SHA-256 hash, hover over the event icon and click the Copy icon GUID-15BD0FB6-15C9-4FB7-B4EE-3AAAFC044B05-low.png.

MD5

Indicates the MD5 hash (32-digit hexadecimal number) of the file.

Tip

Use the MD5 hash for adding exclusions.

Command-Line Parameters

Indicates the context in which the event is generated.



Actor section

Item

Definition

Name

Indicates the name of the process that started the event.

Final Reputation

Indicates the overall reputation and reputation score after the event.

Reputation Score

Initial Reputation

Indicates the overall reputation and reputation score before the event. If the final and initial reputation are the same, then the initial reputation and reputation score is not displayed.

Reputation Score

PID

Indicates a unique identifier for the process.



Reputation scores and definitions

Reputation

Reputation score

Definition

Known Clean Updater

100

A trusted file created by a trusted updater

Known Trusted

99

A trusted file

Most Likely Trusted

85

Almost certainly a trusted file

Might Be Trusted

70

Appears to be a benign file

Unknown

50

Can’t make a determination

Might Be Malicious

30

Appears to be a suspicious file

Most Likely Malicious

15

Almost certainly a malicious file

Known Malicious

1

A malicious file

Not Set

0

No reputation is specified



Disable the Story Graph

Users can choose whether or not they would like to have the Story Graph feature enabled. Story Graph is enabled by default in order to provide valuable context to ATP detections.

  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Adaptive Threat Protection from the Product list.

  2. Click the editable policy.

  3. Click Show Advanced.

  4. In the Story Graph section, deselect the Enable Story Graph Tracing checkbox.

  5. Click Save.

  6. Enforce the policy to the client system.

  7. To validate the Story Graph is disabled on the client system:

    On Trellix ePO - On-prem

    1. Select MenuSystemsSystem Tree and select a group in the System Tree.

    2. Click the system name.

    3. Click Products, then click Endpoint Security Adaptive Threat Protection.

    4. Scroll down to the Options section to view the Story Graph on the client system is disabled.

    (On client system)

    1. Click the Endpoint Security Adaptive Threat Protection module and make sure the Enable Story Graph Tracing checkbox is deselected.