Trellix appliances generate local signatures (also known as observables) based on MVX analysis and DTI intelligence. Helix Enterprise can collect local signatures from eligible appliances, match signature rules to create intelligence feeds (also known as observable feeds), and then share the feeds with all eligible connected appliances in your organization.
In a federated setup, feeds from eligible appliances can be shared across all organizations that have feed sharing enabled. Feed sharing can be enabled on child organizations even if it is disabled on the parent organization.
Signatures in Helix Enterprise observable feeds expire 24 hours after they are created.
For a list of eligible appliances, see the "Software Requirements" section of the Helix Integration Guide.
The following Helix Enterprise feeds are automatically created:
helix-<organization>-feed-md5-block-listhelix-<organization>-feed-url-block-list
Note
A Helix Enterprise feed is treated as a third-party feed on eligible appliances. Helix Enterprise feeds propagated to eligible Network Security appliances can be modified or deleted from the Settings > 3rd Party Feeds page in the Network Security Web UI or the Manage > Appliance Settings > 3rd Party Feeds page in the Helix Enterprise Web UI. Any changes to a Helix Enterprise feed will be overwritten when Helix Enterprise propagates the feed to the appliance in the next cycle.
You can use the fireeye_localsig class to search Helix Enterprise for streamed local signature metadata.
Feed sharing must be enabled for the feeds to be propagated from Helix Enterprise so the signatures can be shared with appliances. Feed sharing can be enabled or disabled at various levels for granular control. Email notifications can be sent if feed propagation fails, as described in Configuring email notifications.
Note
An empty feed is propagated to all eligible appliances if the following are disabled: organization-level sharing, feed-level sharing, and appliance-level sharing. The empty feed changes the signature count on the 3rd Party Feeds page to zero.
A feed is removed from the 3rd Party Feeds page if federated feed sharing is subsequently disabled on the organization that propagated the feed to the appliance.
You can create custom feeds on individual appliances, as described in Custom feeds.