Analyze threat actors, tools and techniques associated with a campaign in Trellix Insights

Prev Next

Trellix Insights illustrates the correlation between an individual campaign, its common threat actors, and MITRE techniques and tools through a graphical representation. It displays the campaigns detected in your environment along with details regarding the threat actors and tactics, techniques, and procedures (TTPs) associated with these campaigns.

TTPs provide additional information in the graph view if there are any campaign-related detections in your environment. If no detections are present, you can apply relevant filters available in the left pane.

You can view the relationship between an individual campaign (and multiple campaigns) and its associated threat actors and tools.

  1. Log on to Trellix Insights.

  2. Click Insights_megamenu_icon.png and select Campaigns to view the list of campaigns under the All Campaigns tab. Alternatively, you can search a specific campaign by Campaign name. You can perform the following actions:

    • Filter (GUID-B39D3406-4908-4CFC-ACFA-FBCEBBD9CF29-low.png) campaigns by Severity, Labels, Profiles, Prevalent in selected sector, and Prevalent in selected country.

    • Sort each column in the Campaigns table—such as Severity, Last Seen, Campaign Name, Sector, Country, and Threat Category.

    • View campaigns prevalent in selected sectors or countries.

    • Add campaigns to the Watch List.

  3. Select the campaign, view the following details and take actions (if required).

    • Description - A brief description of the campaign.

    • Campaign Severity - Severity level of the campaign.

    • Impact Details - Displays whether your environment has detected the campaign.

    • Global Prevalence - List of sectors and countries affected by the campaign.

    • Labels - Labels are comprised of one or more categories of attack or threat actor.

    • Analyzed Indicators - Lists all analyzed IoCs for which campaign detection is possible.

    • Countermeasures - A set of effective countermeasures (if available) to remediate the attack.

    • Endpoint (analyzed indicators only) - Displays the number of campaign sightings or events based on their resolution within the organization.

      • Unresolved - A number of detections and devices where a campaign sighting or event has not been resolved by Trellix ENS.

      • Resolved - A number of detections and devices where Trellix ENS has resolved a campaign sighting or event.

    • Network - Displays the number of campaign sightings or events based on the IOC category and resolution within the organization.

      • Product - NSP

      • IOC category - View the category of the detection: URL, IP or Domain.

      • Unresolved detections - A number of detections and devices where a campaign sighting or event has not been resolved by Trellix IPS.

      • Resolved detections - A number of detections and devices where Trellix IPS has resolved a campaign sighting or event.

    • Content Package - View the number of devices based on their current AMCore Content (for Windows and Linux operating systems) version. Devices in red have insufficient coverage for the campaign. You can click How to update AMCore Content? to view details and links with instructions to improve your protection against this campaign.

  4. Click View Details and go to the Connections page.

  5. On the Connections page, you can search and apply filter(s) available on the left pane. The filter menu on the left side of the screen can be used to add and/or investigate campaigns by threat actor, labels, geographical location, and more. The graph displays campaigns associated with the applied filter(s).

    • Show only common campaigns across categories - This toggle option is disabled by default. To display campaigns matching with all the applied filters, turn on this toggle option.

    • Profiled (Actors/Tools) - Campaigns associated with the selected threat actors or tools provided by the Trellix research team are displayed.

    • Labels - Campaigns and the categories of attack with selected labels are displayed.

    • CVEs - Campaigns associated with the selected vulnerabilities are displayed.

    • MITRE groups - Campaigns associated with selected MITRE techniques are displayed.

    • Threat Actor - Campaigns associated with the selected threat actors are displayed.

    • Sightings and Reportings - Campaigns prevalent or reported in selected sectors or countries are displayed.

    • Other malicious categories - Campaigns associated with the malicious categories are displayed. For example, if you select the Ransomware category, then the campaigns associated with this category are displayed.

  6. To view campaign-related detections in your environment, select the Include TTPs checkbox in the graph. For more information, see Graphical view of campaign detection.

    Note

    The Include TTPs checkbox is enabled only when you select Include Detections checkbox.

  7. To view analyzed indicators for the selected campaign, select the Include all IOCs for this campaign checkbox in the graph.