Trellix Insights provides the latest global intelligence on the top campaigns that threat actors are using to target business sectors and organizations around the world. You can view metrics for your business sector and geo-location and prevalence data for both targeted campaigns and specific security threats that might impact your organization. With this information, you can take preventive action to protect your organization.
Trellix Insights features:
Security Posture Score — Evaluates the overall security score (combination of Endpoint and Cloud scores) of an organization and provides recommendations that can protect your organization. This widget is now found on the Your Detections page.
Threat Landscape — Threat Landscape dashboard provides a comprehensive view of the campaigns and threats that may impact your organization.
Campaigns by Severity — View the number of campaigns detected based on the severity of each campaign — High, Medium, Low.
Campaign Detections — View the number of campaign-related detections in the last 10 days. This metric has been consolidated onto the Your Detections page.
Device exclusions — View the number of devices in your environment that are exposed and those that have insufficient AMCore content coverage for known campaigns. Click the number of systems affected to view details about the Devices and Events page.
Note
Using device exclusion rules to stop particular endpoint devices from being flagged for insufficient content or coverage affects the total number of devices listed.
Campaigns — View detailed information about specific campaigns, your environment, and Indicators of Compromise (IoCs).
Threats — View detailed information about specific non-campaign threats and your network and environment.
CVEs — View detailed information about common vulnerabilities (CVEs) that are associated with campaigns.
Profiles — View detailed information about threat actors and tools profiled by Trellix.
Suspicious correlations — Highlight artifacts found in your environment are not which are not classified as either clean or malicious, but might be indirectly related to known threats or campaigns.
Countermeasures — View sets of tactics and methods that model your behaviors before, during, and after an attack and take necessary actions to proactively defend against the threats most relevant to your organization.
MITRE Explorer — Analyze the correlation between an individual campaign, its common threat actors, and the respective MITRE tools, techniques and sub-techniques.
Integrate IVX Cloud with Trellix Insights for enhanced file scanning — Enable file scanning for malware by integrating Trellix IVX Cloud with Insights.
Command lines: The Command Lines widget provides a list of the specific command strings and arguments executed by threat actors throughout a campaign's attack lifecycle.
Reports — Generate reports to gain visibility into your organization’s threat exposure and global threats.
You can generate Campaign-specific reports for detailed information on tactics, indicators, and affected devices, environment-specific reports to assess your organization's security posture, coverage gaps, and device exclusions and general threat intelligence reports from the Report Library to understand the most prevalent attack campaigns across sectors and geographic regions.