The Rules page lists Trellix indicator of compromise (IOC) and false positive rules that might be triggered on your network. The list includes any custom indicator rules you have created for your environment, even if those indicator rules are not triggered. Use the Rules page to review rules and to mark conditions within them as false positive or true positive. You can also use the Rules page to create and delete custom indicator rules. To access the Rules page, select Rules at the top of the page.
Trellix rules are mostly hidden from view and are stored in the Dynamic Threat Intelligence (DTI) cloud. They appear on this page only when their existence triggers an alert, when the rule is provided by another Trellix appliance, or if the rule is for an unrestricted Trellix indicator. Conditions included in a Trellix rule are only viewable if the condition triggers an alert. When all alerts associated with a rule are removed, the rule and its associated conditions are hidden again. This streamlines your forensic analysis of alerts because only the pertinent rules and conditions are shown.
At the top of the Rules page, you can search for a specific rule by its name, who created it, or its signature. You can also search by condition value (for example, a specific md5 file or DNS).
Click Create Indicator to create a custom indicator. For more information, see Managing IOC rules.
The version of the intelligence downloaded from the Dynamic Threat Intelligence (DTI) cloud and the time of the last download are shown at the top of the page.
.png)
The Rules page includes two tabs: an Indicators tab and a False Positives tab. Each tab has an associated Detail pane. The Detail pane shows details about the indicator or false positive you select on the grid.
Admin, Analyst, Senior Analyst, or Investigator privileges (full access)
Indicators tab
The Indicators tab lists the triggered Trellix rules and custom indicator rules in use in your environment. You can edit and delete custom indicator rules on this tab. See Intelligence (rule) overview.
Click on a column name in the Indicators grid to sort the data in the grid in ascending alphanumeric sequence based on the column data. Click on the column name again to sort the grid data in descending alphanumeric sequence based on the column data. An arrow to the left of the column name indicates how the grid data is sorted.
Field | Description |
|---|---|
![]() | Select an indicator for which you want to take action. If you cannot select an indicator, no actions are possible. |
OS | The operating system environments to which the indicator applies: Windows ( |
Name | The indicator name. Usually these names are created by Trellix and cannot be changed. You can change the name of a custom indicator. |
Active Since | The date and time when the indicator was first detected on the network (Trellix) or added to the system (custom indicator rules). Timestamps in the Web UI are presented in UTC time. |
Created By | The appliance, organization, or person who created the indicator. |
Category | The indicator category. The following categories are possible:
|
Signature | The type of threat detected. This applies to Trellix alerts only. Types include Web infection, Infection match, Malware object, Malware callback, and Domain match. |
Active Conditions | The number of conditions associated with this indicator. This number excludes the conditions that were marked as false positives. |
Hosts With Alerts | The number of hosts that include one or more alerts associated with the indicator of compromise. Click the number in this field to open the Hosts page, filtered for the specific indicator. This allows you to review the alerts for the specific hosts that are affected by the indicator. |
Source Alerts | The number of source alerts associated with this indicator. |
Indicator tab Detail pane
The Detail pane for the Indicator tab includes two tabs that show detailed information about the indicator selected on the Indicator tab. Use the Detail pane to mark an alerting condition as a false positive. Select a condition in the Detail pane and click Mark as false positive.
Tab | Description |
|---|---|
Indicator Details | The specific conditions for the selected indicator, including the types of alerting conditions in the indicator and information about the alerts generated for the alerting conditions. |
Source Alerts | The source alert information associated with the selected indicator. If there are many source alerts, this tab may wrap behind the detail tab and appear to vanish. If this happens, zoom out or expand the width of the browser window. (ENDPT-662) Timestamps in the Web UI are presented in UTC time. |
False Positives tab
False positive conditions appear on the False Positives tab. See Managing false positive rules.
Field | Description |
|---|---|
Marked By | The user name of the person who marked the condition false positive. False positives marked by Trellix are identified as Trellix in this field. |
Marked | The amount of time since the condition was marked false positive. The units of this field vary depending on how long ago the condition was marked false positive. |
Rule Type | The type of rule that has been marked as false positive. Valid values include: IOC (indicator of condition), EXD (exploit detection), or MAL (malware) |
Condition Type | The type of condition. |
False Positive tab Detail pane
The Detail pane for the False Positive tab shows detailed information about any false positive IOC, exploit, or malware selected on the False Positives tab. No Detail pane is shown for false positive malware selected on the False Positives tab.
Use the Detail pane to change a false positive condition back to a real (not false positive) condition. Select a false positive condition in the Detail pane and click Undo False Positive.
Field | Description |
|---|---|
Indicator | The indicator details associated with this false positive. This information includes the indicator name, the user who created the indicator, and the signature. |
False Positive | The condition marked false positive. |
.png)
.png)
.png)
.png)