The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Trellix Provided Indicators

Prev Next

The IOC Streaming module is shipped with a set of pre-configured indicators that are derived from the Supplemental Indicators, available on the FireEye Marketplace. This set is initially installed with the module and the rules are enabled by default. These rules specifically monitor for behaviors on Windows, Mac and Linux. You can interrogate these rules and specify the ones that should be active in your environment. Since these rules are provided by Trellix, you cannot adjust their conditions, remove them or disable the ones that are not necessary. See Table of Trellix Provided Indicators for a list of theTrellix Indicators provided with the IOC Streaming module.Table of Trellix Provided Indicators

These rules contain

  • Weak-signal indicators

    • Intended to demonstrate how this module can be used to collect telemetry. For example:

      • Registry modification

      • Use of Crontab on Linux

  • Detection content that may be well-suited for specific customer environments. This content includes the following categories of indicators:

    • Detection of exploits

    • Detection of malware families and backdoors

    • Attacker tools such as credential stealers or commonly used legitimate utilities

    • Attacker methodologies

  • IOCs used during the MITRE 2021 evaluation.

  • MITRE ATT&CK technique mapping updates.

  • IOC for Windows Elevation of Privilege Vulnerability (CVE-2021-36934).

The breakout of these rules is

  • 638 IOCs

    • 456 Windows

    • 132 Linux

    • 50 macOS

  • Detection categories

    • 10 exploits

    • 5 malware families

    • 7 backdoors

    • 7 credential stealers

    • 47 utilities often used by attackers

    • 562 methodologies / techniques used by attackers