Retrieving ATI details

Prev Next

Important

Release 7.5.0 and higher support for ATI requires a two-way sharing CONTENT_UPDATES license with ATI support on the appliance that collects and displays the threat intelligence. Before you install the two-way sharing license and ATI license, you must upgrade to Release 7.5.0 or higher.

Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about Multi-Vector Virtual Execution (MVX) engine-verified events on Email Security — Server and Network Security appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. This request retrieves the details of the ATI alert, which includes the threat intelligence.

The following diagram shows the types of threat intelligence that ATI provides for malware object alerts, which are triggered by MD5 checksum matches on Email Security — Server and Network Security appliances. For more information about ATI, see the Network Security User Guide.

All_ATI_fig.jpg