The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Vulnerability assessment

Prev Next

Vulnerability Assessment (VA) on the Receiver allows you to integrate data that can be retrieved from many VA vendors.

You can use VA data in several ways.

  • Raise an event's severity based on the endpoint's known vulnerability to that event.

  • Set the system to automatically learn assets and their attributes (operating system and services detected).

  • Create and manipulate the membership of user-defined asset groups.

  • Access summary and drill-down information of the network assets.

  • Change Policy Editor configuration, such as turn on MySQL signatures if an asset is discovered running MySQL.

Use predefined or custom views to access VA data generated by the system.

Note

If you create a view that includes the total number of vulnerabilities, count, or dial component, you might see an inflated count of vulnerabilities. This is because the Trellix Threat Intelligence Services feed is adding threats based on the original vulnerability that the VA source reported.

Trellix maintains rules that map Trellix sigIDs to VINs to references to a Common Vulnerabilities and Exposure (CVE) ID, BugTraq ID, Open Source Vulnerability Database (OSVDB) ID, or Secunia ID. These vendors report CVE and BugTraq IDs in their vulnerabilities.