An alert is a notification that at least one event of interest has occurred. The event may have security impacts or may be of interest based on some other criteria that you have defined. Alerts can be considered as possible candidates for cases.
Note
If your environment has a Trellix Network Security or Email Security — Server appliance, Helix Enterprise shows Network Security- and Email Security — Server-specific alerts in an expanded visual display.
If your environment has a Trellix Endpoint Security (HX) appliance, Helix Enterprise will show host and indicators of compromise (IOC) information in alert details.
Alerts originate from one of the following:
Trellix rules
Tuned Helix Enterprise rules
Customer rules
Intel hits
Helix Enterprise Analytics
Risk describes the overall potential risk to the organization if the alert is a true positive. It is typically used to prioritize alert verification and response activities. Alerts have one of the following risk values:
Critical
High
Medium
Low
Alerts can be in one of the following states:
Open / Reopened
Suppressed
Closed
Helix Enterprise may also display additional information about the alert if that information is available in Mandiant Threat Intelligence, and allows you to pivot to the Mandiant Threat Intelligence Portal.
New alerts are displayed prominently in an Alert box on the Summary Dashboard. Additional details on each alert, as well as actions that can be taken with alerts, are available on the alert details page. A summary of all alerts is available on the Alerts page under the Investigate menu.