Detection on Demand (DoD) event metadata can be streamed to Trellix Helix. This allows you to triage DoD alerts for detection and hunting directly in the Trellix Helix Web UI, and improves alert correlation in Trellix Helix. One regular or retroactive alert is sent to Trellix Helix for each malicious object.
Metadata for all DoD connectors is streamed to Trellix Helix after the Trellix Helix integration is enabled. The metadata is streamed as soon as a submission is complete or a retroactive alert is available in DoD. In the Trellix Helix Web UI, you can use the fireeye_dod class to search for DoD events that were streamed to Trellix Helix.
Log in to the Detection on Demand Portal, available in the AWS Marketplace.
Create a new authorization (API) key.
Add a new Trellix Helix receiver.
Provide a name and your Trellix Helix ID.
Configure your notification and delivery preferences.
Enable the receiver.
For more information, see the DoD Portal documentation here.