Search and investigate campaigns, threat actors and IOCs

Prev Next

You can quickly find campaigns, threats, threat actors, and IOCs all within a single, unified interface.

  1. Log on to Trellix Insights.

  2. Click Insights_megamenu_icon.png and select Threat Landscape.

  3. On the Threat Landscape dashboard, search for campaigns, threat actors or IOCs. The matched results are categorized into:

    Options

    Description

    Top results

    View the top 3 matched results for any hash files, campaigns, indicators, threat actor, tools and techniques, threats, and events. Click the Show All button to view all search results.

    If the searched string is a file hash (MD5 or SHA256) and Trellix Insights has relevant information, a File Details section is displayed under Top Results. This provides information including a classification name and type. Where a searched file has not been identified as clean or malicious, but its static properties resemble a known threat, Trellix Insights displays a similarity.

    1. Trellix Insights displays the list of top matches, with a match percentage in a linear graph.

    2. For each match, file hashes can be selected in the drop down menu, and the following details are displayed:

      • Threats associated with the file hash

      • A description of similarity, by providing details of matches in groups of static attributes in the PE header

    3. When searching for a malicious MD5, the corresponding SHA256 string is also displayed in the search results.

    Campaigns

    View the list of campaigns that match with the search keyword. You can view details such as name (linked to details page), severity, detected time, description, or any other matched field such as MD5, threat actor type, so on. Click the campaign links to navigate to the campaign details page. Your search results are preserved. You can navigate back to the search results by clicking the back button. By default, you can view 10 campaigns in the search results.

    Indicators

    View the indicators with IOC categories — MD5, SHA256, IP address, URL, Domain, Mutex, and Import Hash. By default, you can view 3 related indicators links. Click the indicator links to navigate to the indicator details page. Your search results are preserved. You can navigate back to the search results by clicking the back button. Click the Show All button to view all related indicator links.

    Threat Actor

    View the threat actors that match with the search keyword, their category, and description. By default, you can view 3 related threat actor links. Click the Show All button to view all related threat actor links.

    Tools & Techniques

    View the tool and techniques that match with the search keyword, their category, and description. By default, you can view 3 related tools and techniques links. Click the Show All button to view all related tools and techniques links.

    Threats

    View threats that match with the search key word, their severity, and description. By default, you can view 3 related threat links. Click the Show All button to view all related threat links.

    Events

    View events that match with the search keyword and details such as event time stamp, devices, operating system (Windows or Linux), campaigns, source IP address, MD5, parent MD5, file path, domains connected, IPs connected, and mutexes. By default, you can view 3 related event links. Click the Show All button to view all related event links.

    • Process Trace - Process tracing displays details for processes executed on your endpoints in graph format. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information.

    Playbooks

    View guided steps and effective tactics to implement in each phase in the attack lifecycle (before, during, and after).

    Countermeasures

    View recommended actions such as policy changes or patches that you can review, test, and apply to protect your systems from threats.

    Reports

    The Report Library gives you quick, clear access to the newest threat reports from Trellix Research team. You can see the latest cyber‑attacks, track emerging hacker groups, and find out which domains or regions are being targeted.