Threat detection using IOC rules

Prev Next

Indicators of Compromise (IOCs) are pieces of forensic data, such as file hashes, IP addresses, or registry keys, that identify potentially malicious activity on a network or system. Trellix provides a continuously updated feed of IOCs from the Dynamic Threat Intelligence (DTI) cloud. You can enhance this protection by creating custom IOC rules in Trellix EDR or Forensics workspace.

Create IOC rules using: