Trellix Helix 2025.5

Prev Next

The Trellix Helix 2025.5 release includes new features and enhancements. For more information, refer to the Helix Product Guide.

New features and changes

Trellix Hyperautomation

Integrating Trellix Hyperautomation with Helix enables the creation of automated workflows that provide faster response on threat detection. This allows analysts to focus on understanding attack methodologies and identifying security improvement areas, rather than repetitive manual remediation tasks. Trellix Hyperautomation integrates directly into the alert workflow, allowing SOAR execution of no-code sequences of actions to investigate and mitigate incidents using integrated products that are managed through the Integration Hub in the Helix UI.

Important

Trellix Hyperautomation is available on a trial basis for T-IAM tenants on customer request.

Enhanced alert timeline

The refreshed alert timeline provides immediate access to critical context, including MITRE tactics and techniques, and insights from Trellix intelligence sources. This eliminates the need for navigation, enabling faster alert triage and threat response. The timeline dynamically adapts to the alert's source, displaying the most relevant information. For example, the hostname, device name, and IP address for endpoint alerts, or the sender's email, domain, and attachment type for email alerts.

Rich case notes

Case notes now support Markdown formatting, allowing you to create structured and easily readable notes. This includes the ability to apply bold text, create lists, and highlight important content, improving the clarity of incident documentation.

Alert details enhanced summary view

The Summary tab on the alert details page shows key contextual information about how the alert was triggered, what assets in your environment are affected, and what action you should take to remediate the alert.

  • How the alert was triggered: The source of each alert or event, such as endpoint, email, or network, and when events were first and last detected. For each alert or event, it shows the MITRE tactics and techniques that were used, and the group by field shows the attributes that link the alerts or events. This contextual information helps you understand the attack pattern, allowing you to take the appropriate action on the alert.

  • Which assets are affected: Host-based and network-based asset information from the alerts or events, and their containment status. For host-based alerts or events this is the asset name, and for network-based alerts or events this includes source IP addresses, destination IP addresses, usernames, and email addresses. If there is no host information, Helix analyses the network data and uses either known information, or infers information from the data, to associate it with a known host. This improved data mapping gives a clearer picture of the impact of the attack in your environment.

  • What actions to take: A list of suggested actions you can take on the alert. If integrated, Trellix Hyperautomation workflows and their status are shown. Otherwise, there is a list of suggested manual response actions you can take.

System tag descriptions

Improved descriptions for system tags help you better organize and categorize data. Hover over a system tag in a table or click a row on the Tags page to view its description in a side panel.

Search enhancements

Search for events from anywhere and use TimeWrinkle: You can search for events from any page of the Helix UI with the search icon (HelixConnect_search.png) in the top navigation bar. The query remains available as you move between UI pages so you can add terms to the query to refine your search. When you get the search results, TimeWrinkle allows you to search a period of time around an event of interest to see if other alerts or events were detected.

View parsed fields and raw message in search results: Customize the search results table to include columns for all parsed fields and the raw message (in JSON format). This allows for quick scanning of results to identify key information and other fields of interest, reducing the time to investigate the data.

Other search enhancements include:

  • Use UTC format to select the date and time your search covers.

  • Refine search results from the side panel. For example, you can add a new field to the search.

  • Edit saved searches.

  • Searches run asynchronously, which means you can switch between queries as they are running.

Manage respond integrations from the Integration Hub

Manage all respond (SOAR) integrations directly from the Integration Hub UI. You can configure respond integrations to perform common investigative actions for each integrated product. This is only available to customers on the Trellix-IAM tenant. Users on F-IAM must migrate.

Supported languages

Trellix Helix supports English only.