The Trellix Helix 2024.12 release includes new features and enhancements. For more information, refer to the Helix Product Guide.
New or changed
Searching the data—Helix search uses a single query language to quickly run searches on data that was collected and stored in Helix, as well as data from connected technologies such as other Trellix products and third-party products. A single search interface allows for powerful, customizable queries that pull in relevant data to view and process. All searches are asynchronous and run in the background.
Managing alerts in Helix—Alert management provides the workflow for a security analyst to monitor incoming alerts, validate if the alert is a true positive or false positive, and take response actions to contain, mitigate, and remediate the alert.
Managing cases in Helix—Case management provides the workflow for a security analyst to take one or more related alerts or events, provide additional context, perform manual and automated analysis, and collaborate with team members as they work to contain, mitigate, and remediate an attack.
Managing detection rules—Helix detection rules enable you to manage the volume and efficacy of alerts you monitor regularly without missing new, emerging, or customer-defined threats. Rule management enables you to define a pattern and associate an action to take when the pattern is met. When a rule locates a match (a "hit"), it triggers an alert or a log entry, depending on its configuration. If the detection is covered by an exclusion, the event is ignored.
Using tags in Helix—Tags are metadata that help you identify and sort alerts, cases, and rules. There are two types of tags: system tags and custom tags.
New detection capabilities—The new detection capabilities provide real-time threat detection by automatically loading and updating security rules. It continuously monitors incoming data, applying relevant rules to identify potential threats. The system processes events, generates alerts for detected anomalies, and stores key information for further analysis. It manages rule updates, event states, and alerts across various data sources while preventing redundant notifications.
The Helix Integration Hub—The Integration Hub enables you to add and manage connected third-party security products in Helix. It allows third-party SaaS applications to authenticate and utilize webhooks, and pull and push commands through API connections, so you can integrate your existing applications into Helix without complex custom development. You can ingest data from a variety of sources, including endpoint devices, cloud applications, and network infrastructure.
Supported language
Trellix Helix supports English only.
Removed
In this release, Cloud Connect has been replaced by Integration Hub. Navigate to Integration Hub to access existing integrations or add new ones. No action is required on your part, as all existing integrations have been automatically migrated from Cloud Connect to Integration Hub.
Known issues
No known issues are listed for this release.