Secure your environment by disrupting potential attack paths using Trellix APD

Prev Next

To achieve full visibility and protection, complete the following phases:

  1. Deploy the Trellix APD Package – Deploy  to your Windows endpoints through Trellix ePO - SaaS.

  2. Configure and run discovery scans – Define how and when your systems analyze for risks.

  3. Identify and prioritize high risk paths – Visualize and prioritize potential attack chains in the Trellix APD portal.

  4. Remediate and validate the risk– Fix the identified weaknesses and confirm the risk is eliminated.

Deploy the Trellix APD Package

  1. Log in to Trellix ePO - SaaS.

  2. Go to Advanced Deployment and click New Deployment.

  3. Select the Trellix Attack Path Discovery package.

  4. Choose your target systems from the System Tree and click Save.

  5. Navigate to System Tree → Products to confirm the package is listed with recent scan details.

Configure and run discovery scans

  1. In ePO - SaaS, go to Client Tasks and select Attack Path Discovery from the task types.

  2. Create a New Task, providing a descriptive name.

  3. Assign the task to your systems and schedule it to run at the next Agent-Server Communication Interval (ASCI).

Identify and prioritize high risk paths

  1. Access the  Portal using the link in your  tenancy activation email.

  2. Open the Risk Insights page to view a centralized dashboard of all managed hosts.

  3. Use the Add filter or Order by options to sort the host list by risk level or technical feasibility.

    Note : For detailed instructions on using the  portal, click the help icon  within the  interface.

  4. Click Export as filtered to generate a .xlsx or .pdf report to share it with your team for remediation.

  5. Select hosts with High Risk Scores to view their specific vulnerability attack scenarios.

  6. Review the following:

  • Expand Vulnerability Attack Scenarios to visualize how an adversary could reach critical systems from this host.

  • Check the Exploit Status to identify if any vulnerabilities on the host are actively "weaponized".

  • Review the Factors contributing to Risk to see how specific security weaknesses link together into a dangerous chain.

  • Identify any Exposed Sensitive Assets to determine the business impact if this host is compromised.

  • Review the CVSS Score Breakdown and Exploit Status Breakdown in the left panel to determine if any vulnerabilities are Weaponized.

  • Analyze the Vulnerability Instances Breakdown to see how many findings are categorized as Prioritized for immediate action.

  • Navigate to the Missing Patches section and ensure the filter is set to Unsuperseded to view only the most current updates required.

Remediate and validate the risk

  1. Identify the specific missing patches or configuration changes required to block the identified path.

  2. Apply the necessary updates to the affected endpoints.

  3. Return to Trellix ePO - SaaS and manually run the Attack Path Discovery client task to collect fresh data.

  4. Refresh the Trellix APD dashboard on the Trellix APD portal to verify that the attack path is removed and the host risk level has decreased.