Threat Hunting and Enrichment

Prev Next

Trellix Hyperautomation provides advanced capabilities for SOC analysts to proactively hunt for threats and enrich investigations using unified data and automated actions. These features accelerate the detection and response lifecycle, moving beyond simple alert monitoring to active threat hunting.

Some of the capabilities are:

  • Enrich using third-party intel sources

  • Automated investigation creation based on collected intel

  • Federated Search across the connected apps for SOC analysts

  • Real-time action on search results such as disable a user, quarantine device, kill container, process, block IP, delete confidential file from a unsecured location etc.