Managing alerts

Prev Next

An alert is a notification that at least one event of interest has occurred. The event may have security impacts or may be of interest based on some other criteria that you have defined. Alerts can be considered as possible candidates for cases.

Note

If your environment has a Trellix Network Security or Email Security — Server appliance, Helix Enterprise shows Network Security- and Email Security — Server-specific alerts in an expanded visual display.

If your environment has a Trellix Endpoint Security (HX) appliance, Helix Enterprise will show host and indicators of compromise (IOC) information in alert details.

Alerts originate from one of the following:

  • Trellix rules

  • Tuned Helix Enterprise rules

  • Customer rules

  • Intel hits

  • Helix Enterprise Analytics

Risk describes the overall potential risk to the organization if the alert is a true positive. It is typically used to prioritize alert verification and response activities. Alerts have one of the following risk values:

  • Critical

  • High

  • Medium

  • Low

Alerts can be in one of the following states:

  • Open / Reopened

  • Suppressed

  • Closed

Helix Enterprise may also display additional information about the alert if that information is available in Mandiant Threat Intelligence, and allows you to pivot to the Mandiant Threat Intelligence Portal.

New alerts are displayed prominently in an Alert box on the Summary Dashboard. Additional details on each alert, as well as actions that can be taken with alerts, are available on the alert details page. A summary of all alerts is available on the Alerts page under the Investigate menu.