1. Getting the big pictures

Prev Next

The Dashboard highlights the threats that need immediate attention. This is the correlation used in this example, as shown on the Dashboard.

Helix_ThreatDashboardExample.png

The analyst observes the following information at a glance:

  • The truncated title shows that a Credential Access MITRE tactic using the Command and Scripting Interpreter technique was the first stage of the attack.

  • The correlation is open and assigned to a SOC analyst.

  • Three assets were affected: two hosts and one user.

The risk score for the threat is 568. The analyst hovers over the context card to see the rationale behind the risk score.

Helix_ContextCardExample.png

The analyst clicks the correlation to drill into it. The Correlations Details page opens.

Helix_CorrelationDetailsExampleTop.png

The Overview title and description provide more detail about what happened: Trellix Network Security and Endpoint Security appliances detected but did not block an adversary from attempting the tactic shown on the Dashboard. Four other MITRE tactics were attempted using ten other MITRE techniques. The attempts were made against the "system" user and two hosts.

Of the 14 MITRE tactics seen in the environment, five were attempted in this correlation. The analyst hovers over 5/14 Tactics to see the stages of the attack. Clicking the links in the pop-up window opens the appropriate mitre.org page for deeper knowledge of the tactics and techniques.

The following illustration shows two of the tactics: Credential Access, in which the adversary is attempting to steal account credentials, and Execution, in which the adversary is attempting to run malicious code.

Helix_TacticsPopupExample.png