Trellix source alerts

Prev Next

Source alerts are alerts that match suspicious activity identified by intelligence received from other Trellix products and services. To enable source alerts in your environment, your Endpoint Security (HX) must be integrated with other Trellix products and services.

When integrated with another Trellix product, the Endpoint Security (HX) receives reports of suspicious activity from that product, parses the reports, and creates relevant indicator rules based on actionable data the reports provide. These indicator rules are then automatically shared with the EDRF Client installed on the endpoint. The EDRF Client confirms the presence or execution of matches for these indicator rules on their hosts. Alerts based on matches to indicator rules originating from other Trellix products are called source alerts.

Use the instructions in this topic to view additional information about source alerts on the Rules page in the Endpoint Security (HX) Web UI.

Prerequisites
  • Analyst, Senior Analyst, Investigator, or Admin access

  • An account on the appliance from which the source alert originated.

To view source alert information:
  1. On the Indicators tab of the Rules page, locate indicator rules related to source alerts using any of the following methods:

    • Sort indicator rules on the Indicators tab by category (Custom or Trellix). Trellix indicator rules are the only indicator rules that produce source alerts. In the Indicators grid, click the Category heading and then click the up arrow.

      The indicator rules are reorganized in alphabetical order by category type and the Trellix indicator rules are grouped together.

    • Sort indicator rules on the Indicators tab by the Source Alerts column. Click the Source Alerts heading in the grid and then click the down arrow.

      The indicator rules with the highest number of source alerts appear at the top of the indicator list,

    • Search for a specific indicator rule on the Indicators tab of the Rules page that produced a source alert if you know its name or specific condition. Enter relevant information about the indicator in the Search by name, created by, signature, or condition value box above the grid and press Enter.

      Only indicator rules matching the search conditions appear in the Indicators grid.

  2. Click an indicator. Details about the indicator appear in the Detail pane.

  3. View information about indicator conditions and alerts generated for this indicator on the Indicator Details tab of the Detail pane.

  4. On the Source Alerts tab in the Detail pane, view the following information:

    • The Source Alert Detected area provides timestamps for each source alert related to this indicator. Each of these timestamps is a link. Click the link to view the originating service's report on the Trellix product appliance that generated the related indicator. This report provides important information to help your investigation.

    • The Validated area shows you whether the EDRF Client confirmed a source alert. A check mark in the Validated column indicates:

      • A source alert was associated with the IP address of an endpoint when the Endpoint Security (HX) processed the alert. EDRF Client confirms matches for source alerts on their hosts when Endpoint Security (HX) first processes the source alerts and when agents monitor future activity.

      • EDRF Client found evidence on its host of activity matching one or more conditions of the indicator associated with the source alert.

    Note

    If there are many source alerts, this tab may wrap behind the detail tab and appear to vanish. If this happens, zoom out or expand the width of the browser window.(ENDPT-662)