Trellix Wise enhances your ability to perform investigation of security alerts by providing AI-generated insights and tools. This feature is designed to facilitate remediation through conversational AI, offering actionable investigation tips, suggesting response actions, and supporting efficient alert handling. It also enables analysts to learn more about threat hunting.
Supported Alert Types
Trellix Wise provides enrichment for the following alert types: NDR PX/NX/IPS alerts.
Note
Alerts originating from other sources do not receive Trellix Wise investigation summaries.
Network requirements for Trellix Wise (Secure/Restricted Environments)
To enable Trellix Wise in a secured or restricted NDR deployment, the appliance must be allowed to communicate with the Trellix Wise cloud service.
If outbound communication is blocked by a firewall or web proxy, Trellix Wise enrichment will not function.
Outbound Communication
Allow the following FQDN and IP addresses for outbound HTTPS traffic (TCP 443):
Service | FQDN | IP Address(es) |
|---|---|---|
Trellix Wise Cloud Service | ndr-trellixwise.trellix.com | 35.167.9.106 52.42.228.108 |
These endpoints must be reachable from the NDR to retrieve data, generate investigation summaries, and provide contextual analysis.
Secure Web Proxy Configuration
If your environment routes outbound traffic through a secure web proxy, ensure the following:
The above FQDN/IPs are are allow listed.
TLS inspection does not affect or block the connection.
The NDR Console is configured with the correct proxy settings.
Note
Trellix Wise is supported only for alerts that include metadata providing sufficient contextual information. Currently, Trellix Wise works only with NDR-Sensor, NX, and IPS alerts.
If the selected alerts do not contain L7 metadata, Trellix Wise does not send a request and returns an error. This behavior applies to HX, EX, and AX alerts, which currently do not include the required L7 metadata.
Alerts originating from other sources will not receive Wise investigation summaries.
Click
and from INVESTIGATION, select Alerts.The Alert List page is displayed.
Click any parameters from the Severity, Alert Created, MITRE TTP, Device Type, Status,and Target Port to open the alert panel. Click Trellix Wise.
OR
Click the alert you want to investigate, click
and then select Open Alert Details.
Click
. Select the required prompt for knowing more about the alert.Summarize this alert: Involves condensing alert information into a concise overview, highlighting the main issue and key details.
Top affected entities: Displays key network details such as source IP, destination IP, and destination port associated with the alert.
Note
This feature is available only to users with an Enterprise license.
MITRE findings: Displays technique or sub-technique ID of the associated alert. This ID allows quick reference to detailed information about the technique, including its description, examples, and recommended mitigations.
Remediation steps: Provides details about possible actions taken to address the issue indicated by the alert.
Note
This feature is available only to users with an Enterprise or Core license.
Knowledge graph: Represents the context and entities connected with the associated alert.
Note
This feature is available only to users with an Enterprise or Core license.
This is hidden for Nozomi alerts.
Sequence diagram: A visual diagram illustrating the sequence of steps resulting in the alert.
Note
This feature is available only to users with an Enterprise license.
This is hidden for Nozomi alerts.
Know more: Allows you to enter questions to gather additional details about the alert.
Note
This feature is available only to users with an Enterprise or Core license.