Indicators of Compromise (IOCs) are pieces of forensic data, such as file hashes, IP addresses, or registry keys, that identify potentially malicious activity on a network or system. Trellix provides a continuously updated feed of IOCs from the Dynamic Threat Intelligence (DTI) cloud. You can enhance this protection by creating custom IOC rules in Trellix EDR or Forensics workspace.
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules from EDR workspace