Web infection

Prev Next

Web-infection alerts indicate that the endpoint accessed a Web page that was determined by the MVX engine to exploit the endpoint. Subsequent Web infections are blocked, depending on your configuration.

Check if anything suspicious happened around this time. If you have the Trellix IPS license and known exploit details are available, check if the vulnerable software versions are being used. Check local security logs and SIEM logs. You can also use the Endpoint Security (HX) server for triage investigation.

Starting in the 7.9 release, there are now three flags to differentiate among the types of URLS:

  • URL (not suspicious)

  • Referer.URL

  • Suspicious.URL