The correlation graph provides a visual representation of links between artifacts identified in your environment and known threats and campaigns.
The correlation graph is presented in a left-to-right orientation. It begins with an ePO node on the left, representing the ePO environment used to log into Trellix Insights.
The next node represents the device and displays the System Name. Clicking on this node displays additional device attributes including: IP address, Users, Tags, and Operating System. These details are retrieved from the ePO environment.
The next node represents the artifact identified in your environment. It is with this artifact that Trellix Insights has discovered correlations to known threats or campaigns. Clicking on this node provides basic details of the artifact, including reputation and classification name. If process trace is available, Trellix Insights also provides a link to view the trace.
Note
If this node is displayed due to a static correlation with known malicious files, the match percentage with top matches, threat associated with each of the matched files, and observations relating to attributes in the PE header are displayed when the node is clicked. You may select different file hashes in the drop down menu provided. The edges emitting from the node provide the percentage match in their label.
The edges describe the relationship between connected nodes. If an edge is dotted or dashed, it means the next node was identified in the global telemetry (but may not have been identified in your environment).
Further nodes and edges highlight the complete correlation with known campaigns or threats.
For nodes that are associated with campaigns, the additional detail when clicked includes: Comments, Determinism, and Lethality, where available.
Correlation explanations are provided to explain different correlations presented. It groups correlations with the device at the top level, and provides timestamps of sightings, and descriptions of hashes and URLs.
The graph feature provides a toolbar to zoom in and out, export, and use full screen. At the bottom of the panel, a time-based filter can be used to view correlations for artifacts found only in your environment for the chosen window.
Common edges and labels
Edges | Edge label used |
|---|---|
epo - device | has device |
device - file | observed file |
device - url | observed url |
device - domain | observed domain |
file - url | downloaded from url |
file - domain | downloaded from domain |
url- file | downloads file |
domain - file | downloads file |
to campaign | is associated with campaign |
to threat | is a threat |