Malware alerts
You can use specific information contained in malware rules to create a malware false positive rule. Some malware false positive rules are downloaded from Trellix's Dynamic Threat Intelligence (DTI) cloud to the Endpoint Security (HX). When Endpoint Security (HX) Agents poll the server, all malware false positive rules are automatically applied to the endpoints.
The Endpoint Security (HX) performs the following actions after a malware false positive rule has been defined:
The specific malware information in the malware false positive rule is marked as a false positive for all existing malware alerts that include the malware information, as well as for any new malware alerts that might be created later.
Alerts triggered by the malware false positive rule are marked with a false positive badge but are not removed by default when you defined the malware false positive rule, but you can choose to remove them.
The number of malware alerts affected by malware false positive rules is included in the alert counts on the Alerts and Hosts with Alerts pages.
If a host endpoint only has alerts for the malware false positive rule, the alerts remain on the Alerts and Hosts with Alerts pages, but show a false positive badge.
Removing a user-defined malware false positive rule causes the Endpoint Security (HX) to perform the following actions:
The specific malware information in the malware false positive rule is no longer marked as a false positive for all existing malware alerts that include the malware information. The false positive badge is removed from existing malware alerts that are affected only by the rule.
New malware alerts generate normal malware alerts.
The number of malware alerts affected by malware false positive rules is decreased in the alert counts on the Alerts or Hosts page tabs.
The false positive badge is removed on the Alerts or Hosts with Alerts pages that only had alerts for the malware false positive rule.
Malware false positive rules are removed from the DTI when Trellix determines that the false positive rule is really a true positive. Trellix Endpoint Security (HX) Agents are notified when they next poll the server. When DTI-based malware false positive rules are removed, the following actions happen:
Future occurrences of the malware information used in the true positive rule will generate normal malware alerts.
Existing malware alerts that were marked as false positive alerts while the rule was a false positive rule will continue to be marked as false positive alerts and are not converted to true positive alerts. (ENDPT-9547/ENDPT-9281/ENDPT-10136) This is different from what happens when user-defined malware false positive rules are removed.
Malware false positive rules may be removed from the DTI if the false positive database is full and Trellix determines that the false positive is not a frequent occurrence. The Endpoint Security (HX) continues to show the alert as a false positive.
Indicator (IOC) alerts
Indicators of compromise rules (IOC rules) are composed of conditions. You can mark specific conditions in an IOC to define an IOC false positive rule. You can also remove the IOC false positive rules if you determine they are true positives.
In addition your own IOC false positive rules, Trellix regularly updates intel. When Trellix determines that an IOC is causing false positives, that IOC will be removed from the intel. The next time the Endpoint Security (HX) downloads the updated intel, the IOC causing the false positives will be removed. Endpoint Security (HX) Agents will receive this updated information when they next poll the server.
The Endpoint Security (HX) performs the following actions after an IOC false positive rule has been defined:
The condition included in the IOC false positive rule is marked as a false positive in all existing indicator rules as well as any new indicator rules that might be created later.
The number of active conditions are updated for the indicator rules that include the false positive.
Removing IOC false positive rules causes the Endpoint Security (HX) to perform the following actions:
The underlying condition reappears as active in any existing indicator rules and any future indicator rules that include the condition.
Alerts related to the condition may reappear on hosts.
Counts of active conditions for existing indicator rules that included the condition will increase.
The overall number of alerts on the Hosts page may increase. Hosts that match only this condition may reappear on the page's Hosts with Alerts tab.
Historical conditions
A historical condition is a collateral result of creating an IOC false positive rule. If you delete an indicator that has IOC false positive rules, the conditions in the false positive rules that are associated only with that indicator are orphaned and remain in the system as historical conditions.
You can view historical conditions on the Rules page after you search for the historical condition value on False Positives tab if the condition is marked as false positive. See Searching for false positive rules .
Removing false positive classifications from historical conditions has these results:
The historical condition does not reappear in alerts or as an active condition until someone creates or edits an indicator rule containing it.
The historical condition no longer appears on the Rules page when you search for its indicator rule value.
Exploit alerts
Exploit detection alerts are based on intelligence received from Trellix about a variety of known exploits and online attacks. You can mark an exploit as false positive, and you can remove a false positive rule if you determine the exploit is a true positive.
Important
User-defined exploit false positive rules are not propagated to the Endpoint Security (HX) xAgent. Use exploit false positive rules for marking existing alerts on the Endpoint Security (HX) only.
Trellix provides regular updates to the exploit false positive rules (exclusions) from the Dynamic Threat Intelligence (DTI) cloud to the Endpoint Security (HX).
The Endpoint Security (HX) performs the following actions after an exploit false positive rule has been defined:
The specific exploit in the false positive rule is marked as false positive for all existing exploit alerts that include the exploit information. You can also choose to mark false positives for any new exploit alerts that are created later (see "Mark as False Positive Page" in Marking an alert as a false positive).
Alerts triggered by the exploit false positive rule are marked with a false positive badge but are not removed by default when you define the rule. You can choose to remove them.
The number of exploit alerts affected by exploit false positive rules is included in the alert counts on the Alerts and Hosts with Alerts pages.
If a host endpoint only has alerts for the exploit false positive rule, the endpoint remains on the Alerts and Hosts with Alerts pages but shows a false positive badge.
Generic alerts
You can use the same false positive workflow as you use for legacy alerts to mark generic alerts as false positive. You can mark these alerts as false positive from either the Alerts page or the Alert Details page of the Endpoint Security (HX) Web UI and you can select the specific conditions to consider for the alert. These conditions come from parameters passed by the alerting module.
The Endpoint Security (HX) performs the following actions after you create a generic alert false positive rule:
Alerts matching your false positive rule are no longer generated.
The user marked FP designator appears on the alert.
The false positive rule appears on the False Positive tab of the Alerts page.