After completing configuration, perform these core tasks to secure your network environment.
Validate threat severity
Follow these steps to analyze an active network alert and map its full risk exposure.
Identify an alert indicating active lateral movement inside the Trellix NDR console.
Open the investigation menu for the compromised network host.
Cross-launch the Trellix APD portal directly from the console menu.
Review the visual map to see how attackers can reach critical business assets.
This workflow turns an isolated alert into a strategic risk map.
Prioritize vulnerability remediation
Follow these steps to eliminate large backlogs of critical security patches.
Import vulnerability data from supported scanners like Tenable, Qualys, or Rapid7.
View the unified telemetry and vulnerability analysis inside the portal.
Locate specific network choke points where multiple attack paths intersect.
Remediate a single misconfigured asset to neutralize multiple potential attack paths at once.
This targeted action significantly reduces overall risk exposure with minimal effort.
Verify security controls
Follow these steps to confirm your detection systems function correctly against real-world tactics.
Execute a safe automated attack simulation from the portal.
Monitor the Trellix NDR console for incoming alerts.
Verify that the console successfully detects the simulated adversary techniques.
This validation ensures your existing security controls actively protect your network.