Trellix Insights

Prev Next

Trellix Insights provides the latest global intelligence on the top campaigns that threat actors are using to target business sectors and organizations around the world. When this intelligence is available, you can view it on the Intel tab on the Alert Details or Threat Details page.

In the Most Recent Event section of the Alert Details or Event details page, hover over the colored ‘i’ icon to view the context card for the indicator of compromise (IOC). This shows the threat level, the reason that an IOC was given this threat level, and a list of the threat actors using the IOC. Click on the colored ‘i’ icon to pivot directly to Trellix Insights for more information on the IOC.

IOCs associated with the alert are listed on the Intel tab. When you click on an IOC, Helix Enterprise displays any intelligence that Trellix Insights has on the IOC. The intelligence information is updated each time you click on an IOC. Each IOC can have one or more campaigns associated with it.

Trellix Insights provides the following information, if available, for each IOC and campaign.

Field

Description

Verdict

The threat level of the IOC. The possible values are: Malicious, Suspicious, Indeterminate, and Benign.

IOC First Seen

The date the IOC was first seen by Trellix.

Deterministic Score

How unique the IOC is to the campaign. The possible values are:

  • Very Unique - The IOC is unique and strongly associated with the campaign or threat group.

  • Unique - The IOC is used in multiple campaigns, but is unique to this threat group.

  • Partially Unique - The IOC has unique code segments or could be a vulnerability used, but is not necessarily unique to this campaign or threat group.

  • Commodity - The IOC is part of the campaign or malware sample, but contains few unique elements. It is used by multiple campaigns and multiple threat groups.

  • Non-Deterministic - The IOC is commonly used but not malicious.

  • Unknown - There is not enough data to classify the uniqueness of the IOC.

Comments

More information on the IOC.

Lethality

How lethal the IOC is. The possible values are:

  • Destructive - Definitely malicious and destructive.

  • Malicious - Definitely malicious, but less destructive

  • Malicious Enabler - A malicious tool used to drop a sample.

  • Probable Malicious - No sample is available, but the description of a sample analysis of the source suggests that it is probably malicious.

  • Dual Use - A non-malicious tool that is used maliciously.

  • Unconfirmed - No sample is available for analysis, or there is a lack of data sources to confirm the lethality.

Campaign Name

The name of the campaign.

Description

More context and information on the campaign. For example, information on the victims of the campaign, the threat actors carrying out the campaign, and the method of attack used.

Severity

How severe the campaign is. The possible values are: High, Medium, and Low.

Observed Countries

The countries where this campaign has been prevalent in the last 10 days.

Observed Sectors

The sectors where this campaign has been prevalent in the last 10 days.

For more information, see the Insights Product Guide.