Investigating alerts using Trellix Wise

Prev Next

Trellix Wise enhances your ability to perform investigation of security alerts by providing AI-generated insights and tools. This feature is designed to facilitate remediation through conversational AI, offering actionable investigation tips, suggesting response actions, and supporting efficient alert handling. It also enables analysts to learn more about threat hunting.

Supported Alert Types

Trellix Wise provides enrichment for the following alert types: NDR PX/NX/IPS alerts.

Note

Alerts originating from other sources do not receive Trellix Wise investigation summaries.

Network requirements for Trellix Wise (Secure/Restricted Environments)

To enable Trellix Wise in a secured or restricted NDR deployment, the appliance must be allowed to communicate with the Trellix Wise cloud service.

If outbound communication is blocked by a firewall or web proxy, Trellix Wise enrichment will not function.

Outbound Communication

Allow the following FQDN and IP addresses for outbound HTTPS traffic (TCP 443):

Service

FQDN

IP Address(es)

Trellix Wise Cloud Service

ndr-trellixwise.trellix.com

35.167.9.106

52.42.228.108

These endpoints must be reachable from the NDR to retrieve data, generate investigation summaries, and provide contextual analysis.

Secure Web Proxy Configuration

If your environment routes outbound traffic through a secure web proxy, ensure the following:

  • The above FQDN/IPs are are allow listed.

  • TLS inspection does not affect or block the connection.

  • The NDR Console is configured with the correct proxy settings.

Note

  • Trellix Wise is supported only for alerts that include metadata providing sufficient contextual information. Currently, Trellix Wise works only with NDR-Sensor, NX, and IPS alerts.

    If the selected alerts do not contain L7 metadata, Trellix Wise does not send a request and returns an error. This behavior applies to HX, EX, and AX alerts, which currently do not include the required L7 metadata.

  • Alerts originating from other sources will not receive Wise investigation summaries.

  1. Click Main_menu.png and from INVESTIGATION, select Alerts.

    The Alert List page is displayed.

  2. Click any parameters from the Severity, Alert Created, MITRE TTP, Device Type, Status,and Target Port to open the alert panel. Click Trellix Wise.

    OR

  3. Click the alert you want to investigate, click Browse.JPG and then select Open Alert Details.

  4. Click WISE_icon.png. Select the required prompt for knowing more about the alert.

    • Summarize this alert: Involves condensing alert information into a concise overview, highlighting the main issue and key details.

    • Top affected entities: Displays key network details such as source IP, destination IP, and destination port associated with the alert.

      Note

      This feature is available only to users with an Enterprise license.

    • MITRE findings: Displays technique or sub-technique ID of the associated alert. This ID allows quick reference to detailed information about the technique, including its description, examples, and recommended mitigations.

    • Remediation steps: Provides details about possible actions taken to address the issue indicated by the alert.

      Note

      This feature is available only to users with an Enterprise or Core license.

    • Knowledge graph: Represents the context and entities connected with the associated alert.

      Note

      • This feature is available only to users with an Enterprise or Core license.

      • This is hidden for Nozomi alerts.

    • Sequence diagram: A visual diagram illustrating the sequence of steps resulting in the alert.

      Note

      • This feature is available only to users with an Enterprise license.

      • This is hidden for Nozomi alerts.

    • Know more: Allows you to enter questions to gather additional details about the alert.

      Note

      This feature is available only to users with an Enterprise or Core license.