Trellix Helix metaclasses are defined in the following table.
Metaclass | Definition |
|---|---|
| Events generated by antivirus or similar host-based mechanisms (for example, ClamAV, Symantec, Sophos, McAfee). |
| Any application-based transaction activity, such as an application, database, or similar API transaction record. |
| Events pertaining to authentication or authorization (for example, Single Sign-On (SSO), Active Directory, LDAP, RADIUS, 2FA). |
| Events originating from any cloud-hosted service or product. |
| Connection-based events providing visibility into network protocols (for example, netflow, sflow, jflow, session, connection). |
| Events pertaining to Dynamic Host Configuration Protocol (DHCP) and IP address allocation. |
| Data loss prevention events related to the protection, confidentiality, and integrity of data handling within network, endpoint, and cloud environments. |
| Events pertaining to any method or transaction used to interact with DNS records. |
| Events pertaining to email message transfer (for example, SMTP). |
| File transfer events in any protocol (for example, FTP, HTTP, SMB, BitTorrent). |
| Connection accept/deny events generated by firewalls or similar devices that enforce ACLs on network traffic (for example, VLAN, ACLs). |
| Specialized events providing health metrics for a sensor or server. |
| Outbound Web browsing events processed by an HTTP proxy. Includes events processed by other sources that handle outgoing HTTP traffic. Used in intel matching and Trellix rules and analytics |
| Inbound Web requests processed by a hosted Web server. Includes events generated by other sources that handle incoming HTTP traffic (for example, apache, nginx, firewalls, reverse proxies, load balancers). Used in intel matching and Trellix rules and analytics. |
| Intrusion detection/prevention system events, including network alerts (for example, Snort, Suricata, Bro) or host-based alerts (for example, McAfee HIPS, OSSEC). |
| Network Address Translation (NAT) or Port Address Translation (PAT) events. |
| Events originating from POSIX, Unix, and Linux based services. |
| Events that indicate escalated user privileges (for example, Cisco |
| Site-to-site VPN tunnel events or end-user client-access VPN events. |
| Windows event logs (all types). |