Working with threats

Prev Next

This topic describes basic concepts about threats in HE .

Correlations and alerts

A threat can be either a correlation or an alert. A correlation is a group of related alerts.

  • Correlations are denoted by a folder icon Helix_correlation-icon.png.

  • Alerts are denoted by a triangle icon Helix_alert-icon.png.

Risk score rationale

Risk score rationale is displayed on context cards. To open a context card and see the factors behind the assigned risk score, hover over the correlation or alert icon on the Dashboard, Threats page, Correlations Details page, or Threat Details page.

Helix_threat-risk-score.png

Table graphs

The Threats page includes a graph that displays the data in the table below it. To hide or show the graph, toggle the Visualization switch.

Helix_threats-table.png

Threat graphs

Threat graphs display a summary of an incident and allow you to zoom into the details of the execution in the environment for further threat hunting. The graphs connect the dots between Trellix and third-party alerts. By default, the graphs have collapsed nodes.

Helix_threats-graph.png

You can expand a node to see details. When you click a collapsed or expanded node, the context details open on the right side of the graph.

Helix_threats-graph-expanded.png

Assets

An asset can be either a user or a host.

  • Users are denoted by a person icon Helix_ThreatUserIcon.png.

  • Hosts are denoted by a computer monitor icon Helix_threat-host-icon.png.