Threat activity intelligence is collected by Trellix and made available to the Endpoint Security (HX) products as indicator of compromise (IOC) rules (also referred to as indicator rules or IOC rules) via Trellix’s Dynamic Threat Intelligence (DTI) cloud.
Real-time indicator monitoring uses Trellix indicator rules to detect many suspicious activities, including the following:
Unauthorized use of valid accounts
Trace evidence and partial files
Command and control activity
Known and unknown malware
Suspicious network traffic
Valid programs used for malicious purposes
Unauthorized file access
Trellix indicator rules are provided for Windows, macOS, and Linux endpoints.
Real-time indicator detection is disabled by default. You must enable it on the Policies page. You should add all of your exclusions before enabling this feature.
For more information, see Intelligence (rule) overview.
For a list of specific credentials that are monitored by real-time indicator detection, see "Legal Tokens and Types" in the Endpoint Security (HX) REST API Guide
Custom indicator creation
You can create custom indicator rules that identify threats you have identified in your own environment, such as the establishment of specific network connections, DNS lookups, and the creation or modification of specific files. The combination of Trellix indicator rules and your custom indicator rules make up the full set of real-time indicator rules used for real-time indicator monitoring by Endpoint Security (HX) Agents.
Important
Endpoint Security (HX) version 4.8 or later supports the creation of custom indicator rules for Linux conditions (network events only).
For more information, see Managing IOC rules.
Real-time indicator policy
You can use the Endpoint Security (HX) Web UI to create a custom policy, edit the Agent default policy, or list specific files and folders that should be excluded from real-time indicator detection. When this policy is enabled, the specified files and folders are excluded from real-time indicator detection.
Note
You can assign a custom policy to a host set. The Agent default policy applies to all hosts. For more information about policies, see the Endpoint Security Agent (HX) Administration Guide.
Trellix indicator rules are provided for Windows, macOS, and Linux endpoints.