Suspicious correlation

Prev Next

Suspicious correlation highlights artifacts found in your environment are not which are not classified as either clean or malicious, but might be indirectly related to known threats or campaigns.

Examples of suspicious correlations include:

  • A file hash is identified in your environment. On examination of global telemetry, the file was found to have been downloaded from a known malicious URL.

  • A URL is accessed in your environment. On examination of global telemetry, this URL was found to have been contacted by file hashes associated with a known campaign.

  • A file hash is observed in your environment. On examination of the static properties in the header of this PE file, it bears structural resemblance with known malicious files.

The Suspicious correlation tab is displayed only when Trellix Insights identifies correlations matching the above criteria in the artifacts received in Trellix ENS telemetry.

When Trellix Insights identifies a correlation, a one-time pop-up is displayed on the Trellix Insights dashboard to introduce users to the Suspicious correlation feature and the tab location.