Hyperautomation

Prev Next

Hyperautomation orchestrates security workflows, called playbooks, allowing you to automate, schedule, or manually run response actions based on NDR alerts. The integration enables you to perform retroactive searches for Indicators of Compromise (IOCs) across historical network data. This capability helps your security team identify threats that went undetected at the time, improving operational efficiency.

Automated incident response with Hyperautomation

NDR integrates with Trellix Hyperautomation to streamline incident response and automate manual security tasks. This integration speeds up incident resolution, reduces manual effort, and strengthens network security.

With this integration, you can:

  • Automate data flow smoothly from detection through response.

  • Link specific alert categories to workflows in Hyperautomation.

  • Let workflows automatically and manually respond to threats when alerts in linked categories trigger.

You can configure the NDR to automatically and manually trigger predefined workflows in Hyperautomation when it detects threats. This allows you to respond immediately by blocking IP addresses, isolating hosts, or creating incident tickets in third-party systems.

Note

Adhere to the established workflow lifecycle when creating or editing workflows. This includes phases such as creation, testing, deployment, and versioning.

Important

You can refer to the Trellix Hyperautomation product guide for a detailed understanding of the workflow lifecycle phases.