Configure Trellix APD

Prev Next

To build attack maps, complete the initial portal configuration. Collect asset telemetry and connect your vulnerability scanner API.

Collect endpoint telemetry using the Trellix APD agent

Prerequisites: Configure your firewall to permit outbound access to the Trellix APD tenant.

Ensure the following rules are active:

  • NDR to trellix-apd.com on TCP Port 443.

  • NDR to trellix-apd.com on TCP Port 44305.

  • Endpoints to trellix-apd.com on TCP Port 44305.

  1. Log in to the Trellix APD portal.

  2. Select the Scanning tab.

  3. Download the script for your operating system.

    • The Windows script is named deepsurface-windows-ephemeral.ps1

    • The Linux script is named deepsurface-linux-ephemeral.sh

    • The macOS script is named deepsurface-macos-ephemeral.sh

  4. Open your command-line interface with administrator privileges on the endpoint.

  5. Bypass the execution policy if the system blocks the script.

  6. Run the script.

Note

The script automatically downloads the lightweight agent. The local scan typically completes in 2 to 5 minutes. The scanning status displays as “not applicable” until data processing is complete. Data processing in the cloud requires 8 to 10 hours. View the processed intelligence in the Risk Insights tab.

Manual testing workflow

Follow these steps to manually start the job for testing purposes.

  1. Go to the ActivityTasks page on the Trellix APD portal.

  2. Click Process in the Process Scan Queue.

  3. Enable the checkbox to run the next task in sequence when finished.

    The system manually processes the inputs and imports the vulnerability data and risk analysis.

  4. View the updated information on the Risk Insights page after all jobs complete.

Import vulnerability data from Tenable Security Center

Note

Tenable Security Center must use a publicly accessible IP address to synchronize with the cloud tenant. The portal retains imported vulnerability data for 30 days. You must re-import scans periodically.

  1. Log in to the Trellix APD portal.

  2. Select Settings.

  3. Select Vulnerability Sources.

  4. Select your Tenable environment. Options include Tenable.io, Tenable SaaS, or SecurityCenter Tenable.sc API.

  5. Type the public hostname, administrative username, and password.

  6. Select Save and Test Integration to verify communication with the tenant.

  7. Select Import to pull scan results into the portal.