Profiles — Your Environment

Prev Next

Click to view how the threat profile has affected the devices in your organization.

  1. Log on to Trellix Insights.

  2. Click Insights_megamenu_icon.png and select Adversary and Tools. The list of threat actors (adversaries) and the tools and techniques used by these threat actors are displayed.

    Item

    Description

    Devices Exposed

    View the number of exposed devices in your environment.

    Detections Timeline

    View the number of events for the threat profile in the organization along a timeline.

    • Click and drag your mouse to move the timeline back and forth.

    • Use the mouse wheel to scroll through the timeline.

    Select Last day, Last week , or Last month to change the scale of the timeline.

    Your ENS Devices

    Select these tabs to view a list of devices in your environment.

    • Devices Exposed — View devices where the threat event is not remediated.

    • Devices with insufficient coverage — View devices that do not have the minimum AMCore Content version.

    • All Impacted Devices — View all devices that have IoCs for this campaign.

    For each device you can view the following:

    • System Name — Click to view the system in the System Tree.

    • IP Address

    • Last communicated

    • Current AMCore Content

    • Resolved Detections

    • Unresolved Detections

    • Last Detected

    Your Network (NSP)

    For each device you can view the following:

    • IOC Category

      • IP

      • URL

      • Domain

      • IP:Port

      • Hostname

    • IOC Value

    • Total Detections

    • Resolved Detections

    • Unresolved Detections

    • Last Detected

Event Details — Your ENS Devices

Click a System name to view event details for the device.

Item

Description

System name

View the name of the selected system. Click to view the system in the System Tree.

Detection Timeline

Select an option to view events by timeline.

Detection Date

View the detection date.

Search

Use search to filter the list of events.

Events

View a list of Events and the time stamp of the event.

Details

View details of the event:

  • EndPoint Details

    • Product Name

    • Product Version

    • AMCore Content Version

  • File Details

    • IoC Type

    • IoC Value

    • PE Product Name

    • PE Product Version

    • PE Publisher Name

  • Execution Details

    • File Path

  • Mark this event as resolvedTrellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the time stamp, and other comments. Use the filter option to filter events based on their resolution status (Resolved or Unresolved).

  • Process Trace - Process tracing displays details for processes executed on your endpoints in graph format. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information.

Event Details — Your Network (NSP)

Click to view event details the device.

Item

Description

Detection Timeline

Select an option to view events by timeline.

Detection Date

View the detection date.

Search

Use search to filter the list of events.

Events

View a list of Events and the time stamp of the event.

Details

View details of the event:

  • Product Details

    • Product Name

    • Product Version

  • IOC Details

    • IP, URL, or Domain

    • Attack Name

    • Attack Type

    • Detection Mechanism

    • Category

    • Sub-Category

  • Execution Details

    • Application Name

    • Direction of attack

    • NSP Protocol

    • Source IP address

    • Source Port

    • Source DNS Name

    • Destination IP address

    • Destination Port

    • Destination DNS Name

  • Mark this event as resolvedTrellix Insights allows you to mark an unresolved event as resolved. Where Exposed Devices or Unresolved Detections are displayed, click a device to view Product Details, IOC details, Execution Details, and a Mark as Resolved button. Once an event is resolved, the event is marked as resolved and a small icon displays (representing manual resolution). Select Details > Manual Resolution to view who resolved the issue, the time stamp, and other comments.