This alert indicates that the endpoint generated suspicious traffic and the MVX engine returned a positive match. Zero-day callbacks are only enabled on Dynamic Threat Intelligence (DTI) two-way licenses because data must be sent to DTI to validate this threat. The endpoint is likely compromised because standard browsing traffic will not trigger this type of dynamic alert. The endpoint should be investigated immediately and removed from the network during the process. Check local security logs and SIEM logs. You can also use the Endpoint Security (HX) server for triage investigation.
Malware callback (DTI.callback)
- Published on Aug 25, 2026
- 1 minute(s) read
Was this article helpful?
Related articles
- Network Security (NX) > Common Security Platform Product Docs > Trellix Alert Notifications ( CEF | LEEF | CSV | XML | JSON ) > Overview > Alerts
- Network Security (NX) > Common Security Platform Product Docs > Trellix Alert Notifications ( CEF | LEEF | CSV | XML | JSON ) > CEF notifications > Sample CEF notifications per event type
- Network Security (NX) > Common Security Platform Product Docs > Trellix Alert Notifications ( CEF | LEEF | CSV | XML | JSON ) > Overview > Alerts
- Network Security (NX) > Network Security SmartVision Feature Guide > Monitoring > Managing alerts > Critical malware detection panel