Trellix Helix effectiveness depends on the data sources available for analysis. The log data that you send determines Trellix Helix's detection capability (such as use cases available). From the perspective of effective use of Trellix Helix, there are varying types of log data.
The Trellix Helix Communications Broker Sender has specifications for log data accepted and log data from specific sources that are currently supported. Trellix Helix generally accepts logs from log aggregation systems and other sources such as network devices, security systems, and operating systems.
The following table shows information about the data sources.
Data Source | What is Collected | How Logs are Used in Trellix Helix |
|---|---|---|
Connection Logging | Logs connection information and duration between two hosts. | Identify APT activity from known bad IP addresses. Track movement of malicious hosts around the network. |
DNS Logging | All DNS requests are logged. | Identify malware or APT activity. |
Files Logging | Names/hashes of files are logged. | Identify malicious files used by attackers, or invalid versions of files. |
SMTP Logging | Logs all SMTP headers. | Identify internal spam abuse or augment SMTP logs. |
HTTP Logging | Similar to proxy/Web server logs, but does not include user names. | See attacks on internal Web servers or malware leaving an egress. |
SSL Certificate Logging | Logs certificate information such as CA. | Identify known bad certificates or invalid certificate chains. |
Tunnel Logging | Identify and report on tunneled traffic, such as teredo, IPv6 over IPv4, or GRE. | Identify possible data exfiltration or command and control. |
Software Logging | Detect versions of applications in use. For example, old Java versions, Web browser versions, and so on. | Identify abnormal or vulnerable software in use. |