Metaclass definitions

Prev Next

Trellix Helix metaclasses are defined in the following table.

Metaclass

Definition

antivirus

Events generated by antivirus or similar host-based mechanisms (for example, ClamAV, Symantec, Sophos, McAfee).

app_transaction

Any application-based transaction activity, such as an application, database, or similar API transaction record.

auth

Events pertaining to authentication or authorization (for example, Single Sign-On (SSO), Active Directory, LDAP, RADIUS, 2FA).

cloud

Events originating from any cloud-hosted service or product.

connection

Connection-based events providing visibility into network protocols (for example, netflow, sflow, jflow, session, connection).

dhcp

Events pertaining to Dynamic Host Configuration Protocol (DHCP) and IP address allocation.

dlp

Data loss prevention events related to the protection, confidentiality, and integrity of data handling within network, endpoint, and cloud environments.

dns

Events pertaining to any method or transaction used to interact with DNS records.

email

Events pertaining to email message transfer (for example, SMTP).

file_xfer

File transfer events in any protocol (for example, FTP, HTTP, SMB, BitTorrent).

firewall

Connection accept/deny events generated by firewalls or similar devices that enforce ACLs on network traffic (for example, VLAN, ACLs).

health

Specialized events providing health metrics for a sensor or server.

http_proxy

Outbound Web browsing events processed by an HTTP proxy. Includes events processed by other sources that handle outgoing HTTP traffic. Used in intel matching and Trellix rules and analytics

http_server

Inbound Web requests processed by a hosted Web server. Includes events generated by other sources that handle incoming HTTP traffic (for example, apache, nginx, firewalls, reverse proxies, load balancers). Used in intel matching and Trellix rules and analytics.

ids

Intrusion detection/prevention system events, including network alerts (for example, Snort, Suricata, Bro) or host-based alerts (for example, McAfee HIPS, OSSEC).

nat

Network Address Translation (NAT) or Port Address Translation (PAT) events.

posix

Events originating from POSIX, Unix, and Linux based services.

privilege

Events that indicate escalated user privileges (for example, Cisco enable, sudo, runas, Windows impersonation).

vpn

Site-to-site VPN tunnel events or end-user client-access VPN events.

windows

Windows event logs (all types).