You can view details about the campaign such as the campaign description, its severity level, the global prevalence of the campaign, the AMCore Content coverage, and other details.
Log on to Trellix Insights.
Click
and select Campaigns. The list of campaigns are displayed under the All Campaigns tab. Alternatively, you can search a specific campaign by Campaign name. You can perform the following actions:Filter (
) campaigns by Severity, Labels, Profiles, Prevalent in selected sector, and Prevalent in selected country.Sort each column in the Campaigns table—such as Severity, Last Seen, Campaign Name, Sector, Country, and Threat Category.
View campaigns prevalent in selected sectors or countries.
Add campaigns to the Watch List.
Select the campaign, view the following details and take actions (if required).
Description - A brief description of the campaign.
Campaign Severity - Severity level of the campaign.
Impact Details - Displays whether your environment has detected the campaign.
Global Prevalence - List of sectors and countries affected by the campaign.
Labels - Labels are comprised of one or more categories of attack or threat actor.
Analyzed Indicators - Lists all analyzed IoCs for which campaign detection is possible.
Countermeasures - A set of effective countermeasures (if available) to remediate the attack.
Endpoint (analyzed indicators only) - Displays the number of campaign sightings or events based on their resolution within the organization.
Unresolved - A number of detections and devices where a campaign sighting or event has not been resolved by Trellix ENS.
Resolved - A number of detections and devices where Trellix ENS has resolved a campaign sighting or event.
Network - Displays the number of campaign sightings or events based on the IOC category and resolution within the organization.
Product - NSP
IOC category - View the category of the detection: URL, IP or Domain.
Unresolved detections - A number of detections and devices where a campaign sighting or event has not been resolved by Trellix IPS.
Resolved detections - A number of detections and devices where Trellix IPS has resolved a campaign sighting or event.
Content Package - View the number of devices based on their current AMCore Content (for Windows and Linux operating systems) version. Devices in red have insufficient coverage for the campaign. You can click How to update AMCore Content? to view details and links with instructions to improve your protection against this campaign.
Click View Details.
In the Campaign Overview page, view the following details:
Option
Description
Description
A brief description of the campaign.
Severity
Severity level of the campaign. The possible values are: High, Medium, or Low.
Knowledge Base
Knowledge Base articles that provide more information about the campaign.
Labels
Campaign labels such as APT, Botnet, Rootkit, Ransomware, and more, that help you categorize your campaigns and provide insights into the nature of a threat.
Labels are comprised of one or more categories of attack or threat actor that are applicable to the selected campaign.
Common Vulnerabilities and Exposures (CVE)
CVE IDs associated with the threat profile.
Coverage
A minimum level of AMCore Content coverage required to protect against the campaign.
Last Detected
The last detected time stamp of the campaign in your organization.
Countermeasures
A set of effective countermeasures designed to increase preparedness and remediate in anticipation of an attack.
Global Prevalence
The list of sectors and countries where this campaign has been prevalent (with impacted devices and a color-coded map). Global prevalence is based on the number of detections in the last 7 days. Trellix Insights has detected the presence of associated IOCs in these countries in the last 10 days.
Infection Comparison
The infection comparison pane displays the number of devices affected by the campaign in your organization against the selected business sector and country in the last 7 days.
A red dot indicates affected devices.
Hover over the dot to see the number of infections compared to the total number of devices.
The size of the dot indicates the proportion of infected devices to the total number of devices.
Sector and country show the number of infections per million devices.
Trellix Products detecting this threat globally
View the detection distribution for the campaign or IoC grouped by Trellix products:
By Products — Distribution of detection of Trellix products.
By Versions — Click a product in the ring to view the distribution of versions of a selected product.
ENS scanners — Distribution of ENS Scanners. For example, JCM, AVSCAN.
Analyzed Indicators
View all analyzed IoCs for which campaign detection is possible. Indicators detected in your environment are highlighted in blue. You can copy the IOC values by clicking the copy icon and search for them in other Trellix products. You can also export the list of analyzed indicators and campaign details in STIX 2 format.
Other Associated Indicators
View campaign indicators that are informational only. Campaign detections do not occur based on these IoCs. You can copy the IOC values and also export the list of analyzed indicators and campaign details in STIX 2 format.
Threat Behavior
You can view the following information about MITRE techniques:
MITRE Techniques Observed — View the list of MITRE techniques and MITRE attack IDs for the campaign.
Details — A brief description of the corresponding MITRE technique.
Other Information — View campaign metadata. Click each of these options for more details about the campaign.
Threat Actor
MITRE Tool
MITRE Intrusion Set
ATT&CK Matrix for Enterprise
Visualize your organization's detection coverage across your portfolio of Trellix products and analyze how active threats use specific techniques.
Other Links
You can view external links to sites that provide information about the campaign.
Command Lines
The Command Lines widget displays actionable data about the attack processes used by threat actors.
To view the Command Lines widget, you must first apply a filter or select a product from the Select Products dropdown menu within the MITRE Matrix. The widget includes the following details:
Command Line: The specific command string and options executed by a program, for example, cmd.exe /c wbadmindelete catalog -quiet.
Technique ID: The associated MITRE ATT&CK IDs, for example, T1059.003, T1490.
Tools: The utilities identified in the command execution, for example, VSSAdmin, wbadmin.
Description: A brief explanation of the command’s role within the program execution.
Click Export to download the displayed command line data in CSV format for use in your organization's internal forensic or hunting workflows.