Trellix Helix architecture

Prev Next

Your Helix architecture comprises two environments: your network environment and a Helix Virtual Private Cloud (VPC) within Amazon Web Services (AWS). Inside your network environment you will have one or more network sensors that stream data directly to Helix or transmit data through a Communications Broker Receiver in the Helix VPC. The Communications Broker Receiver and all other Helix components within the VPC are managed by the Trellix Operations Team.

The types of Helix network sensors are described below.

  • Evidence Collector (EC) edition sensor is a virtual network security sensor with an Evidence Collector FIREEYE_APPLIANCE license. It is the default Helix network security sensor. EC edition sensor runs on a simplified virtual Network Security appliance that uses Suricata to generate L7 metadata events, which you can filter, from network traffic and streams these to Helix. EC edition sensor can also stream third-party logs directly to Helix. It supports the Tapsender, Communications Broker, event filter, and data streaming features. It does not offer detection.

    Note

    You can also enable the Evidence Collector module on a physical Network Security appliance. For more information, see the Network Security User Guide.

    EC edition sensor is integrated with Helix the same way any other Network Security appliance is integrated. For more information, see the Trellix Helix Integration Guide.

  • Cloud Collector is a Zeek-based version of Evidence Collector that runs on a CentOS minimal distribution. It is a Trellix-managed network sensor that contains both the Communications Broker Sender and a network security monitor, which performs analysis and generates metadata about the network traffic it observes and transmits. Cloud Collector can be a Trellix hardware appliance or a virtual appliance that you install on your server or virtual machine. For more information, see the Cloud Collector Installation Guide.

    Note

    Cloud Collector is being replaced by Evidence Collector. For more information, click here.

  • Communications Broker Sender allows log data to be collected and forwarded to Helix.

    There are two types of Communication Broker:

    • Managed Communications Broker Sender is a Trellix-managed software appliance installed from the same ISO image you would use to install a Cloud Collector on your server or virtual machine. For more information, see the Cloud Collector Installation Guide.

    • Unmanaged Communications Broker Sender is installed from the Trellix Communications Broker Sender package (cbs-installer-x.x.xxx) onto your server or virtual machine, and allows log data to be collected and forwarded to Helix. Trellix does not manage or monitor these network sensors, but the sensors will perform the same functions as their managed counterpart. You are responsible for installing, configuring, monitoring, and updating the system. For more information, see the Unmanaged Communications Broker Installation and Configuration Guide.

The basic data flow for the EC edition sensor and Unmanaged Communications Broker Sender:

  1. The Comm Broker or the EC edition sensor receives logs and event data in your environment and streams them to Helix.

    Important

    All data in transit, including all metadata, is encrypted using SSL/TLS. Customer data is never stored in clear text.

  2. Log data is parsed according to the Helix taxonomy, and then indexed to make it available for fast searching and pivoting. Log data that cannot be parsed is still indexed as raw messages.

  3. Both Trellix-defined and customer-defined rules are applied to the events and alerts are generated, if applicable.

  4. Trellix Intelligence is also applied to all events in real time and alerts are generated for any hits.