Local infection

Prev Next

Local-infection alerts happen after a malicious binary or exploitative server traffic is detected. If the Network Security appliance is in blocking mode, local infections are blocked. The exact URL location that the threat was accessed from is detected or blocked in the future, depending on your settings.

Check if anything suspicious happened around this time. If you have the Trellix IPS license and known exploit details are available, check if the vulnerable software versions are being used. Check local security logs and SIEM logs. You can also use the Endpoint Security (HX) server for triage investigation.