Alert operations

Prev Next

The top of the details page contains the most common operations.

  • Alert ID and Name—A unique assigned number and description of the alert.

  • Risk Level—The risk level assigned to the alert.

  • Tags—The tag or tags associated with the alert. If the alert has events with MITRE Att&ck IDs, the tag includes the MITRE technique and ID. You can hover over the tag to see a description of the technique. If you click the icon next to the tag, the mitre.org page that contains additional details about the technique and related sub-techniques opens.

  • Alert Source—Displays an icon for the alert source (Log Events or Trellix Network Security, Endpoint Security (HX), or Email Security — Server alerts) and a list of the events that led to the alert.

  • Assign—The email address of the assignee or "Not Assigned". Use this button to assign the alert. See Assigning alerts.

  • Assess—Assess this alert as a True Positive or False Positive. The icon displays the threat assessment specification. See Assessing an alert.

  • Add to Case —The case numbers to which the alert is assigned. Use this button to assign the alert to a case. See Adding alerts to cases.

  • Export—Send the alert to a CSV or JSON file. See Exporting alerts.

  • Open—View or change the alert status. See Closing and reopening alerts and Suppressing alerts for more information.

  • Investigation—The number of alerts related to a Mandiant Managed Defense (MD) investigation that are mapped to this Helix Enterprise alert. Click the Investigation link to open the Managed Defense investigation detail page in the Managed Defense portal. (Managed Defense alerts are not shown on the Helix Enterprise Alerts page.)

    Note

    This section is displayed only if you subscribe to Mandiant Managed Defense and Trellix enabled the integration with Helix Enterprise.