Investigate the Indicators of Compromise (IOCs) connected to the campaign

Prev Next

Trellix Insights displays a list of Indicators of Compromise (IOCs) consisting of MD5, SHA256, URLs, IP addresses, and file hashes related to a campaign, and facilitates real-time searching in Trellix EDR for further investigation of the IOCs.

  1. Log on to Trellix Insights.

  2. Click Insights_megamenu_icon.png and select Campaigns to view the list of campaigns under the All Campaigns tab. Alternatively, you can search a specific campaign by Campaign name. You can perform the following actions:

    • Filter (GUID-B39D3406-4908-4CFC-ACFA-FBCEBBD9CF29-low.png) campaigns by Severity, Labels, Profiles, Prevalent in selected sector, and Prevalent in selected country.

    • Sort each column in the Campaigns table—such as Severity, Last Seen, Campaign Name, Sector, Country, and Threat Category.

    • View campaigns prevalent in selected sectors or countries.

    • Add campaigns to the Watch List.

  3. Select the campaign, view the following details and take actions (if required).

    • Description - A brief description of the campaign.

    • Campaign Severity - Severity level of the campaign.

    • Impact Details - Displays whether your environment has detected the campaign.

    • Global Prevalence - List of sectors and countries affected by the campaign.

    • Labels - Labels are comprised of one or more categories of attack or threat actor.

    • Analyzed Indicators - Lists all analyzed IoCs for which campaign detection is possible.

    • Countermeasures - A set of effective countermeasures (if available) to remediate the attack.

    • Endpoint (analyzed indicators only) - Displays the number of campaign sightings or events based on their resolution within the organization.

      • Unresolved - A number of detections and devices where a campaign sighting or event has not been resolved by Trellix ENS.

      • Resolved - A number of detections and devices where Trellix ENS has resolved a campaign sighting or event.

    • Network - Displays the number of campaign sightings or events based on the IOC category and resolution within the organization.

      • Product - NSP

      • IOC category - View the category of the detection: URL, IP or Domain.

      • Unresolved detections - A number of detections and devices where a campaign sighting or event has not been resolved by Trellix IPS.

      • Resolved detections - A number of detections and devices where Trellix IPS has resolved a campaign sighting or event.

    • Content Package - View the number of devices based on their current AMCore Content (for Windows and Linux operating systems) version. Devices in red have insufficient coverage for the campaign. You can click How to update AMCore Content? to view details and links with instructions to improve your protection against this campaign.

  4. Click View Details and go to the Indicators of Compromise (IOCs) page .

  5. In the Indicators of Compromise (IOCs) page, you can view and filter the list of IOCs by IOC Type, Insights Type, Category, Determinism and Lethality. You can also use the Export option to export data in CSV format. Trellix Insights provides the following information, if available, for each IOC.

    • IOC Type - The type of IOCs such as SHA256, MD5, file hashes, URLs, IP addresses.

    • IOC Value - Unique value of each IOCs.

    • Category - IOCs are categorized based on the MISP data model. The categories are:

      • Payload Delivery - Information about the initial delivery method of the malware payload, including the email address or web address, vulnerability, originating IP address, and so on.

      • Artifacts Dropped - Artifacts (files, registry keys, and others) left behind by malware.

      • Network Activity - Information about network traffic caused by malware.

    • Insights Type - The available values are: Analyzed and Other Associated. Only the analyzed indicators are used to detect campaigns whereas other associated indicators are informational only and are not used for campaign detection.

    • Comments - Information provided by the Threat Intelligence Group (TIG) while researching the campaign.

    • Determinism - Each IOC is assigned a score indicating how unique the IOC is to the campaign. This means if an IOC is found in a customer's environment, how likely is it that it belongs to this campaign. The possible values are:

      Numerical value

      Level

      Description

      99

      Very unique

      The IOC is unique and strongly associated with the campaign (or threat) group.

      70

      Unique

      The IOC is used in multiple campaigns, but is unique to this campaign (or threat) group.

      50

      Partly unique

      The IOC has unique code segments or could be a vulnerability used, but is not necessarily unique to this campaign or threat group.

      30

      Commodity

      The IOC is part of the campaign or malware sample, but contains few unique elements. It is used by multiple campaigns and multiple threat groups.

      20

      Non-deterministic

      The IOC is commonly used but not malicious.

      10

      Unknown

      There is not enough data to classify the uniqueness of the IOC.

    • Lethality - Each IOC is assigned a score indicating how lethal the IOC is. The possible values are:

      Numerical value

      Level

      Description

      99

      Destructive

      Definitely malicious and destructive.

      70

      Malicious

      Definitely malicious, but less destructive.

      50

      Malicious enabler

      Malicious tools are used to leave behind samples.

      30

      Probable malicious

      No sample is available, but the description of a sample analysis of the source suggests that it is probably malicious.

      20

      Dual use

      A non-malicious tool that is used maliciously.

      10

      Unconfirmed

      No sample is available for analysis, or there is a lack of data sources to confirm the lethality.

    • Prevalent in Sectors - The sectors where this campaign has been prevalent in the last 10 days.

    • Prevalent in Countries - The countries where this campaign has been prevalent in the last 10 days.

    • Added on - The time when this IOC was added to Trellix Insights.

    • First seen by Trellix - The time when Trellix first received the file for this hash.

    • First detected in your environment - The time when this IOC was first seen in your environment. Trellix Insights limits campaign detections to a 180-day time frame.

    • Last detected in your environment - The time when this IOC was last detected in your environment.

  6. Select an IOC from the list and click Real-Time Search in Trellix EDR at the bottom of the page. You are redirected to the Trellix EDR user interface where you can search for the required IOC for further investigation.

    Note

    You must have an active Trellix EDR subscription to use this option. Make sure that your user account has Trellix EDR scope. Make sure that File Hashing Policy is configured on Trellix EDR. For more details on this policy, see File Hashing policy configuration.