Threat activity intelligence is collected by Trellix and made available to the Endpoint Security (HX) products as indicators of compromise (also referred to as indicators or IOCs) through Trellix 's Dynamic Threat Intelligence (DTI) cloud.
Endpoint Security uses the Real-Time Indicator Detection (RTID) feature to detect suspicious activities on your host endpoints. RTID monitoring uses Trellix indicators to detect the following:
Unauthorized use of valid accounts
Trace evidence and partial files
Command and control activity
Known and unknown malware
Suspicious network traffic
Valid programs used for malicious purposes
Unauthorized file access
See "Real-Time Indicator Detection" in the Endpoint Security (HX) Server User Guide for more information.