Proactively defend your environment with Countermeasures

Prev Next

Countermeasures provide specific, actionable recommendations such as policy configurations, patches, or system checks—to strengthen your security posture against known threats. You can implement Active protections (to block or disrupt threats) or Passive monitoring (to detect threats) across the entire attack life cycle: Before, During, and After an incident.

Countermeasures allow you to:

  • Filter defenses based on the attack stage (Before, During, After) or type (Active, Passive).

  • Assess your current configuration against recommended best practices.

  • Execute step-by-step actions to mitigate specific threats.

  • Track your remediation progress by marking actions as complete.

Access and prioritize Countermeasures

You can filter countermeasures based on the phase of the attack or the type of defense required to focus on the most critical gaps in your environment.

  1. Log on to Trellix Insights and navigate to Countermeasures from the main menu.

  2. Use the Selection Pane at the top to filter the list:

    • Attack stage: Select Before, During, or After to focus on preventative measures, active response, or post-attack remediation.

    • Defensive Type: Select Active (actions that deny, degrade, or disrupt threats) and Passive (actions that monitor or detect threats).

  3. Review the list of Countermeasure Outcomes to find recommendations relevant to your environment.

  4. (Optional) Use the search bar to find specific outcomes or click Customize Columns to adjust the visible data (such as Tools, Techniques, or Platform).

  5. (Optional) Click Export to download the list of currently filtered countermeasures for offline analysis. The selected countermeasures, including their detailed actionable steps, are downloaded in JSON or YAML format.

Mitigate threats with guided Countermeasure actions

You can identify a countermeasure and review the specific outcome for each countermeasure and the specific threat it mitigates. Once you have identified, execute the specific, step-by-step actions required to assess your current status and apply the protection.

  1. Select a countermeasure from the list. A details pane opens on the right side of the screen.

  2. Review the Outcome section to understand the goal (For example, "Proactive security prevention for unauthorized entry vectors" or "Find applications using known Win32 API Calls").

    • Review the Stage, Type, Capabilities (required products, for example, ENS), and Platform.

    • If applicable, click the linked campaign name to see the specific threat associated with this countermeasure. This helps you prioritize actions based on active threats targeting your environment.

    • (Optional) Add notes (limited to 300 characters) to keep track of your progress.

  3. In the countermeasure details pane, click View Actions.

  4. Expand the relevant action category to see step-by-step instructions:

    • ASSESS: Expand this section to run checks (such as command-line queries) that determine if your system is currently vulnerable.

    • CONFIGURE: Expand this section to see the specific steps required to implement the fix. This may include applying a Group Policy Object (GPO), editing a registry key, or deploying a specific product policy.

    • VALIDATE: Use the steps in this section to verify that the configuration change was successful.

    • MONITOR: Learn how to set up ongoing monitoring to detect if the threat attempts to bypass your new controls.

  5. (Optional) Click Mark as Complete once you have successfully implemented the action to track your progress. This updates the progress tracker for that countermeasure.

  6. If a specific action is not applicable to your environment, click Ignore.

  7. (Optional) Export these countermeasure actions that can be downloaded in JSON, YAML, PDF or CSV format.