Trellix EDR assigns a severity level to each threat, detection, and alert. The severity level ranges from s0 to s5, where s0 is the least severe and s5 is the most severe. Endpoints return this value in the severity field.
Severity | Level | Description |
|---|---|---|
s0 | Informational | Informational alerts. No confirmed malicious activity. |
s1 | Low | Low-severity detections. |
s2-s3 | Medium | Medium-severity detections. |
s4-s5 | High | High-severity detections. |