The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Set up cyber threat management

Prev Next

Set up feeds to retrieve indicators of compromise from remote sources. You can then use these feeds to generate watchlists, alarms, and reports that allow users to access related IOC activity in your environment.

  1. On the system navigation tree, click System Properties.

  2. Click Cyber Threat FeedsAdd.

  3. On the Main tab, enter the feed name.

  4. On the Source tab, select the source data type and its connection credentials.

    Note

    The supported sources include Trellix Intelligent Sandbox and MITRE Threat Information Exchange (TAXII).

  5. Click Connect to test the connection.

  6. On the Frequency tab, identify how often the feed pulls the IOC files (pull frequency) and the daily trigger time.

    Available pull frequencies include: every x minutes, daily, hourly, weekly, or monthly.

  7. On the Watchlist tab, select which property or field in an IOC file to append to an existing watchlist.

    You can add watchlists for any supported property or field.

  8. If the watchlist you need does not yet exist, click Create New Watchlist. For more information, see the Set up cyber threat feed for domain.

  9. On the Backtrace tab:

    1. Select to analyze events, flows, or both.

    2. Indicate how far back (in days) to analyze the events and flows.

    3. Specify actions to take if the backtrace finds a data match.

    4. For alarms, select an assignee and severity.

  10. On the Main tab, select Enabled to activate the feed and click Finish.