The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Response

Prev Next

The response is newline terminated text base that is a combination of boundary tags, message header information and JSON message payload.

--Boundary_300_380661968_1587754355337
TS: 1587751687198
BTS: 1587751687198
MID: f9b04b28bf4c87f3
SID: app-processor
CID: baAHA18PHEgdx80GtPZyiI
AID: HX
TPC: HX_ALERTS
Content-Disposition: form-data; name="HX_ALERTS"; filename="HX"
Content-Type: application/binary

{"type":"alert","producer":"app-
processor","subtype":"PROCESS_TRACKER","data":{"_id":5,"agent":{"_id":"6Kk3YlsJus6dTm1E9zS3yc","url":"
/hx/api/v3/hosts/6Kk3YlsJus6dTm1E9zS3yc","containment_state":"normal"},"event_at":"2020-04-
24T18:07:20.115Z","matched_at":"2020-04-24T18:07:20.115Z","reported_at":"2020-04-
24T18:07:48.571Z","source":"PROCESS_TRACKER","subtype":null,"matched_source_alerts":[],"resolution":"A
LERT","is_false_positive":false,"decorators":[],"md5values":["cdea299dea8bc934eb375607633ded20"],"deco
rator_statuses":[],"url":"/hx/api/v3/alerts/5","condition":null,"indicator":null,"event_id":null,"even
t_type":null,"event_values":[{"id":"alert--ff8367cb-1451-4a1d-88b0-
e715dcf162ef","type":"alert","name":"Malicious Process cdea299dea8bc934eb375607633ded20
Started","alert_type":"PROCESS_TRACKER","action_nature":"tasking-immediate","description":"Malicious
Process cdea299dea8bc934eb375607633ded20 Started","start_time":"2020-04-
24T18:07:20.115Z","alert_context":["event--79920691-91a0-5345-b53a-39afe34db2da","finding--644ad639-
b5fa-49e0-968f-
1c7b556ca305"],"parameters":{"md5":"cdea299dea8bc934eb375607633ded20"},"object_status":"active","objec
t_source":"Endpoint","created":"2020-04-24T18:07:48.528Z","modified":"2020-04-
24T18:07:48.528Z"},{"id":"eventlog--9ac4b4a6-3af0-4641-93ce-
644a7771f9b8","type":"eventlog","extensions":{"cef-log-
ext":{"meta_information":{"categoryTechnique":"Malware","categoryDeviceType":"Process
Tracker","categoryTupleDescription":"Process Tracker found a compromise
indication","categoryOutcome":"Success","categoryBehavior":"Found","categorySignificance":"Compromise"
}}}},{"id":"file--79920691-91a0-5345-b53a-
39afe34db2da","type":"file","name":"RandomEvent.exe","file_extension":".exe","file_path":"C:\\Program
Files\\RandomEvent\\RandomEvent.exe","size_in_bytes":2272432,"file_created":"2016-10-
16T01:19:22.000Z","file_last_modified":"2016-10-16T01:20:22.000Z","file_last_accessed":"2016-10-
28T18:26:12.144Z","is_archive":true,"is_compressed":false,"is_encrypted":true,"is_hidden":false,"write
":true,"hashes":[{"hash_algorithm":"md5","value":"cdea299dea8bc934eb375607633ded20"}],"object_status":
"active","object_source":"Endpoint","created":"2020-04-24T18:07:48.528Z","modified":"2020-04-
24T18:07:48.528Z","owner_user":"BUILTIN\\Administrators","owner_group":"wheel","digital_signatures":["
digital-signature-info-type--0d9619a3-048e-4da4-8684-7c70b4208bf0"]},{"id":"file--2cca9aa5-a3a9-5969-
b2c8-
1b5a7e6f5a1e","type":"file","name":"explorer.exe","file_extension":".exe","file_path":"C:\\Windows\\ex
plorer.exe","object_status":"active","object_source":"Endpoint","created":"2020-04-
24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"process--2b652c42-970a-4720-bc40-
bc44de64a2f5","type":"process","pid":11864,"binary":"file--79920691-91a0-5345-b53a-
39afe34db2da","parent":"process--cc72747d-cd9d-4d29-b8f1-
ad93afc6bb86","object_status":"active","object_source":"Endpoint","created":"2020-04-
24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z","arguments":"\"C:\\Program
Files\\RandomEvent\\RandomEvent.exe\""},{"id":"process--cc72747d-cd9d-4d29-b8f1-
ad93afc6bb86","type":"process","pid":2032,"binary":"file--2cca9aa5-a3a9-5969-b2c8-
1b5a7e6f5a1e","object_status":"active","object_source":"Endpoint","created":"2020-04-
24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"finding--644ad639-b5fa-49e0-968f-
1c7b556ca305","type":"finding","risk_nature":"malicious","object_status":"active","object_source":"End
point","created":"2020-04-24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"software--
79920691-91a0-5345-b53a-
39afe34db2da","type":"software","name":"Enricher","object_status":"active","object_source":"Endpoint",
"created":"2020-04-24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"action--735adbdc-
6553-5b19-b6f4-2ceca35afafd","type":"action","name":"process-
start","action_nature":"observed","start_time":"2020-04-24T00:00:00.000Z","objects":["process--
2b652c42-970a-4720-bc40-
bc44de64a2f5"],"object_status":"active","object_source":"Endpoint","created":"2020-04-
24T18:07:48.528Z","modified":"2020-04-24T18:07:48.528Z"},{"id":"event--79920691-91a0-5345-b53a-
39afe34db2da","type":"event","event_type":"start","name":"process-event observed and
analyzed","start_time":"2020-04-24T00:00:00.000Z","objects":["file--79920691-91a0-5345-b53a-
39afe34db2da","process--2b652c42-970a-4720-bc40-bc44de64a2f5","finding--644ad639-b5fa-49e0-968f-
1c7b556ca305","software--79920691-91a0-5345-b53a-
39afe34db2da"],"object_status":"active","object_source":"Endpoint","created":"2020-04-
24T00:00:00.000Z","modified":"2020-04-
24T00:00:00.000Z","account_name":"FIREEYE\\matthew.tardiff"},{"id":"analysis--79920691-91a0-5345-b53a-
39afe34db2da","type":"analysis","name":"enrich-context","action_nature":"tasking-
immediate","is_automated":true,"performer":"software--79920691-91a0-5345-b53a-
39afe34db2da","parameters":{"hash":"cdea299dea8bc934eb375607633ded20"},"results":["finding--644ad639-
b5fa-49e0-968f-1c7b556ca305"]},{"id":"relationship--4baee7d9-d716-4ee3-beec-
e2d0508d0ab9","type":"relationship","source":"event--79920691-91a0-5345-b53a-
39afe34db2da","target":"analysis--79920691-91a0-5345-b53a-
39afe34db2da","relationship_type":"triggered"},{"id":"digital-signature-info-type--0d9619a3-048e-4da4-
8684-7c70b4208bf0","type":"digital-signature-info-
type","signature_verified":true,"signature_exists":true,"certificate_issuer":"C=US, S=Washington,
L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA
2011","certificate_subject":"sha256"}]}}
--Boundary_300_380661968_1587754355337