The hunting rules provided by Trellix Advanced Threat Research are code-based custom rules that you can apply to protect your environment from known campaign (or threat) attacks.
Log on to Trellix Insights.
Click
and select Campaigns to view the list of campaigns under the All Campaigns tab. Alternatively, you can search a specific campaign by Campaign name. You can perform the following actions:Filter (
) campaigns by Severity, Labels, Profiles, Prevalent in selected sector, and Prevalent in selected country.Sort each column in the Campaigns table—such as Severity, Last Seen, Campaign Name, Sector, Country, and Threat Category.
View campaigns prevalent in selected sectors or countries.
Add campaigns to the Watch List.
Select the campaign, view the following details and take actions (if required).
Description - A brief description of the campaign.
Campaign Severity - Severity level of the campaign.
Impact Details - Displays whether your environment has detected the campaign.
Global Prevalence - List of sectors and countries affected by the campaign.
Labels - Labels are comprised of one or more categories of attack or threat actor.
Analyzed Indicators - Lists all analyzed IoCs for which campaign detection is possible.
Countermeasure - A set of effective countermeasures (if available) to remediate the attack.
Endpoint (analyzed indicators only) - Displays the number of campaign sightings or events based on their resolution within the organization.
Unresolved - A number of detections and devices where a campaign sighting or event has not been resolved by Trellix ENS.
Resolved - A number of detections and devices where Trellix ENS has resolved a campaign sighting or event.
Network - Displays the number of campaign sightings or events based on the IOC category and resolution within the organization.
Product - NSP
IOC category - View the category of the detection: URL, IP or Domain.
Unresolved detections - A number of detections and devices where a campaign sighting or event has not been resolved by Trellix IPS.
Resolved detections - A number of detections and devices where Trellix IPS has resolved a campaign sighting or event.
Content Package - View the number of devices based on their current AMCore Content (for Windows and Linux operating systems) version. Devices in red have insufficient coverage for the campaign. You can click How to update AMCore Content? to view details and links with instructions to improve your protection against this campaign.
Click View Details and go to the Hunting Rules page.
On the Hunting Rules page, select the rule which includes Trellix Defense rules, Yara rules, Snort rules and Sigma rules. You can filter each of these rules based on different categories. For each rule, the categories available are:
Trellix Defense rules - ENS-Expert to view Trellix ENS Expert rules.
Yara rules - Payload delivery
Snort rules - Network activity
Sigma rules - Payload delivery and Payload installation.
Click the copy icon to copy the rule and search for further investigation.