The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Streaming indicators and conditions

Prev Next

Trellix provided indicators

The IOC Streaming module is shipped with a set of pre-configured indicators that are derived from the Supplemental indicators, available on the FireEye Marketplace. This set is initially installed with the module and the rules are enabled by default. These rules specifically monitor for behaviors on Windows, macOS and Linux. You can interrogate these rules and specify the ones that should be active in your environment. Since these rules are provided by Trellix, you cannot adjust their conditions, remove them or disable the ones that are not necessary. See Table of Trellix provided indicators for a list of theTrellix indicators provided with the IOC Streaming module.

  • Weak-signal indicators

    • Intended to demonstrate how this module can be used to collect telemetry. For example:

      • Registry modification

      • Use of Crontab on Linux

  • Detection content that may be well-suited for specific customer environments. This content includes the following categories of indicators:

    • Detection of exploits

    • Detection of malware families and backdoors

    • Attacker tools such as credential stealers or commonly used legitimate utilities

    • Attacker methodologies

  • IOCs used during the MITRE 2021 evaluation.

  • MITRE ATT&CK technique mapping updates.

  • IOC for Windows Elevation of Privilege Vulnerability (CVE-2021-36934).

  • 638 IOCs

    • 456 Windows

    • 132 Linux

    • 50 macOS

  • Detection categories

    • 10 exploits

    • 5 malware families

    • 7 backdoors

    • 7 credential stealers

    • 47 utilities often used by attackers

    • 562 methodologies / techniques used by attackers