Tabs

Prev Next

Tabs at the bottom of the alert details page provide the following information:

  • Timeline—Displays interactive events that are associated with this alert over time, including correlated alerts.

  • Automations—Shows the playbooks triggered by this alert and all actions completed or pending. This tab is available for cloud Endpoint Security (HX) alerts only. It is not available for on-premises Endpoint Security (HX) alerts.

  • Investigative Tips—Provides steps for investigating alerts, based on the experience of industry experts. For more information, see Viewing investigative tips.

  • Intel —Provides threat assessment information associated with individual indicators of condition (IOCs) in the event. See Viewing intelligence details on alerts.

  • Events—Displays all events that are associated with the alert.

    For alerts sent from a Trellix appliance, the Events tab includes controls that allow you to manage alerts. For details, see Remediating appliance alerts.

    Note

    An email notification is sent when the alert is generated. Additional events (and assets, in the case of asset-based alert correlation) may be attached to the alert after it is generated. This could result in a discrepancy between the numbers in the the email notification and the numbers on the Events and Affected Assets tabs.

  • Affected Assets—Displays any assets (hosts and users) associated with the alert.

  • History—Lists any changes that have been made to the case (for example, change in assignment). See Viewing alert revision history.

  • Notes—Lets you add notes to the case and see any notes that were added previously.

  • OS Changes—Lets you monitor OS changes in malware samples sent from integrated appliances. A graph displays the flow of activity from one OS change type to another, allowing you to track the activities leading up to and following malicious OS changes. (The window that opens when you click the explanation field on the Events tab includes an os-changes section that shows the OS changes in JSON format.)

    For details about monitoring OS changes, see the User Guide for your integrated appliance.

Note

If your environment has a Trellix Network Security or Email Security — Server appliance, Helix Enterprise shows an expanded visual display, including device name and ID, type of alert, virus name, operating system impact, path, host, user agent, and referrer URL.