Analyze campaigns, threat actors, tools and techniques in Trellix Insights

Prev Next

Trellix Insights illustrates the correlation between multiple campaigns in your environment and their common threat actors, tools, and CVEs. A graph view displays the campaigns detected in your environment along with details regarding the threat actors and tactics, techniques, and procedures (TTPs) associated with these campaigns.

Graphical view of campaign detections in Trellix Insights TTPs provide additional information in the graph view if there are any campaign-related detections in your environment. If no detections are present, you can apply relevant filters available in the left pane.

  1. Log on to Trellix Insights.

  2. Click Insights_megamenu_icon.png and select Campaigns, then navigate to the Campaign Connections tab.

  3. On the Campaign Connections page, you can search and apply filter(s) available on the left pane. The filter menu on the left side of the screen can be used to add and/or investigate campaigns by threat actor, labels, geographical location, and more. The graph displays campaigns associated with the applied filter(s). For example, selecting the threat actor APT33 displays all the information related to its campaign . The following filters are available.

    • Show only common campaigns across categories - This toggle option is disabled by default. To display campaigns matching with all the applied filters, turn on this toggle option.

    • Profiled (Actors/Tools) - Campaigns associated with the selected threat actors or tools provided by the Trellix research team are displayed.

    • Labels - Campaigns and the categories of attack with selected labels are displayed.

    • CVEs - Campaigns associated with the selected vulnerabilities are displayed.

    • MITRE groups - Campaigns associated with selected MITRE techniques are displayed.

    • Threat Actor - Campaigns associated with the selected threat actors are displayed.

    • Sightings and Reportings - Campaigns prevalent or reported in selected sectors or countries are displayed.

    • Other malicious categories - Campaigns associated with the malicious categories are displayed. For example, if you select the Ransomware category, then the campaigns associated with this category are displayed.

  4. To view campaign-related detections in your environment, select the Include TTPs checkbox in the graph. For more information, see Graphical view of campaign detection.

    Note

    The Include TTPs checkbox is enabled only when you select Include Detections checkbox.