Analyze campaigns in Trellix Insights

Prev Next

Trellix Insights receives telemetry feeds from network security devices such as Intrusion Prevention System (IPS) and endpoint security devices such as ENS and EDR. If the telemetry contains IOCs such as file hashes, MD5, SHA256, or IP addresses, a campaign is detected, and Insights notifies you of the campaign detection.

You can perform a detailed analysis of the selected campaign in the following order. This will enable you to review the complete attack lifecycle and proactively increase the level of protection of your environment against the campaign attack.