All Indicators of Compromise that were extracted during the analysis are shown on the IOCs page. If an IOC is extracted during analysis, then your system may have been compromised. The name, MD5 hash, and SHA256 hash are displayed for the main object and any associated files.
IOCs
- Published on Aug 24, 2026
- 1 minute(s) read
Was this article helpful?
Related articles
- Insights > Trellix Insights Product Guide > Investigate and respond to threats and campaigns > Analyze campaigns in Trellix Insights
- Insights > Trellix Insights Product Guide > Investigate and respond to threats and campaigns > Adversary and Tools > Adversary and Tool Profiles
- Insights > Trellix Insights Product Guide > Investigate and respond to threats and campaigns > Threats > Threats table > Threats expanded view
- Network Security (NX) > Common Security Platform Product Docs > Trellix Alert Notifications ( CEF | LEEF | CSV | XML | JSON ) > CEF notifications > Sample CEF notifications per event type