Analyze threats with Generative AI

Prev Next

Trellix EDR generates a significant amount of data, necessitating additional support or resources to analyze and respond to any potential threats quickly and effectively. Trellix Wise, a new Generative AI feature, enhances Trellix EDR capabilities with the knowledge graph and backing of real-time analysis to make data-driven decisions, optimize operations, and enhance customer experience. This feature enhances usability and helps you quickly analyze vast amounts of data generated by Trellix to reduce the meantime to respond to threats.

For more information about the Trellix Wise capability, watch this video.

Currently, Trellix Wise is available in the Monitoring dashboard, Device Search, Real Time Search, and Historical Search.

The Trellix Wise feature in both the Monitoring dashboard and Device Search includes a language selection option, allowing you to perform analysis in your preferred language. The built-in caching feature ensures that your selected language is retained and results are returned in that language.

Note

The available languages are English, French, Italian, Portuguese, Spanish, Japanese, Korean, Thai, Hindi, Chinese, and German with English set as the default.

The Trellix Wise feature in Monitoring dashboard and Device Search allows for two types of analysis methods, Interactive mode and Dossier mode, where the default analysis method is Interactive mode. You can use Interactive and Dossier modes to leverage the Trellix Wise capabilities on the user interface. For more information on capabilities of Trellix Wise in Device Search dashboard, see Search for historical data on a single endpoint.

Note

The Ask Wise functionality allows users to leverage Trellix Wise features in the Monitoring dashboard and Device Search, while the Search with Wise functionality enables the utilization of Trellix Wise capabilities in Historical Search. For more information on capabilities of Trellix Wise in Historical Search, see Search for historical data on multiple endpoints

Interactive mode

Interactive mode is an interactive feature that allows you to select different analysis options to get in-depth information about a threat.

  1. On the Monitoring dashboard, select a threat and click on Ask Wise.

  2. On the Ask Wise page, choose Interactive mode and click on Triage.

    Under Interactive mode, you are presented with various analysis options, as shown below.

    • Detection analysis — includes summary and key points about a threat based on the Trellix Wise analysis.

    • Related MITRE TTPs — shows the MITRE analysis related to events and detections. The analysis includes the tactics and techniques that the adversary used during the attack life cycle.

    • More details — provides an updated analysis of the key points with additional details.

    • Knowledge graph — shows the pictorial representation of events executed during the attack life cycle. Access to the Knowledge graph is provided on both the Monitoring page and Device Search page.

      The Knowledge Graph in Interactive mode shows nodes along with their Process IDs (PIDs), each color-coded to reflect severity based on threat analysis. The designated colors are Red for High severity, Orange for Medium severity, Yellow for Low severity, and Blue for zero or no severity.

      The Knowledge graph also features click-and-drag functionality for improved navigation and detailed analysis.

      Note

      The Knowledge graph is exclusively accessible in Interactive mode and not available in Dossier mode.

    • Assess Accuracy — allows you to assess the detection details and related suspicious indicators for an accurate investigation.

    • Suggested Actions — shows the recommended action to take for a particular threat. Additionally, the Suggested Actions pane includes direct links to remediation actions in the Monitoring and Device Search dashboards. This allows you to perform any remediation action directly from the Suggested Actions pane, removing the need for manual navigation.

      The remediation actions in the Monitoring dashboard include Kill Process, Quarantine Host, Shut down Host, Exclude Threat, and Dismiss Threat.

      The remediation actions in the Device Search dashboard include Kill Process, Remove File, Delete Registry Value, Delete Folder, Quarantine Host, and Shut down Host.

    • Device Information — lists the suspicious endpoint information with details such as device name, username, OS name and versions, and IP address.

    • Related breaches — compares the breach details with high-profile known public domain breaches reported in the industry.

    • Draft Mail — uses a predefined template to create a draft that highlights key findings from the Wise analysis. After the draft is created, you can click the email icon to open the default email client with the draft message or click Copy Content button to copy the text to your clipboard.

    Tip

    Any analysis you perform in Interactive mode with the help of Ask Wise in Monitoring dashboard will be cached. The next time you request the same information, the cached data is provided, enhancing the user experience by reducing response time and improving efficiency. This feature was previously available only in Dossier mode

Dossier mode

Dossier mode summarizes the output of the Ask Wise analysis for a particular threat. The summary and recommendations are presented in a section format on the user interface.

  1. On the Monitoring dashboard, select a threat and click Ask Wise.

  2. On the Ask Wise page, choose Dossier mode and click Triage.

    Under Dossier mode, you are presented with the following analysis options

    • Summary — includes summary and key points about a threat based on the Trellix Wise service.

    • Findings — provides details regarding a particular threat such as malicious files executed along with their paths and process IDs, commands executed and techniques involved (if any) to perform certain actions.

    • MITRE Techniques and Tactics — shows the MITRE analysis related to events and detections. The analysis includes the tactics and techniques that the adversary used during the attack life cycle.

    • Known Breaches — provides an updated analysis of the key points with additional details by observing the similarities of the methods, processes used in earlier breaches.

    • Suggested Actions — shows the recommended action to take for a particular threat.

The below mentioned Trellix Wise functionalities are available in both Interactive and Dossier modes. You can utilize these functionalities based on the requirement.

Print threat analysis

The print option allows you to print detailed analysis performed on a threat, including all the chosen analysis options. You can use this feature to directly print the analysis performed or save the performed analysis in PDF format. The print option has been enabled for both Interactive mode and Dossier mode.

Print_option.PNG

Note

When you print or save the threat analysis in Interactive mode, the information from the Knowledge graph will always be positioned at the end of the document.

Feedback system

You can provide feedback on the assistance received from the Trellix Wise service. The feedback system includes a rating option, allowing you to rate the support from 1 (poor service) to 5 (excellent service). Additionally, you can include constructive comments in the Additional Feedback section.

Feedback_system.PNG

Enable or Disable Trellix Wise

Trellix provides you with an option to enable or disable the Trellix Wise feature based on your needs. If you prefer to focus solely on the Trellix EDR services without utilizing the additional functionalities provided by Trellix Wise, you can easily disable it.

To do this, go to MenuConfigurationWise Settings and toggle the switch to enable or disable the feature.

Enable_Disable_Wise.png

When the Trellix Wise feature is disabled, the Wise feature will not be displayed on the Monitoring dashboard, Device Search, Real Time Search, and Historical search. Additionally, the quota displayed in the Quota Management system on the Trellix EDR Support page will show a default count of Zero (0). This level of flexibility enables you to customize your experience to better meet your specific needs.

Note

If you have opted out of Trellix Wise services but would like to explore the capabilities offered by Trellix Wise in the future, you can enable the toggle under Wise settings in Configuration to access the service as a trial user.

Configure the default email client for Draft Mail

Use the Draft Mail capability in Interactive mode to send threat analysis details or copy the analysis content to the clipboard. After you analyze an event or threat using Trellix Wise, use this feature to populate an email with the analysis results. This capability is available only in Interactive mode.

To open your email client automatically, you must first configure a default email client in your web browser.

Note

The Draft Mail icon is disabled if the analysis or user content exceeds 2,000 characters.

Follow these steps to configure a default email client in your web browser.

For Google Chrome or Chromium-based browsers:

  1. Open the Chrome browser.

  2. Enter chrome://settings/handlers in the address bar.

  3. Select Sites can ask to handle protocols.

  4. Open a new tab and enter the URL of your preferred email client. For example, mail.google.com or outlook.office.com.

  5. Click the Service handler icon (angle brackets) in the address bar.

  6. Select Allow, then click Done.

  7. Go to StartSettingsAccounts.

  8. Select Add account.

    Note

    You must remove existing accounts before you add a new account.

  9. Select the account type that matches your browser handler, such as Google or Office 365.

  10. Complete the sign-in process to synchronize the system default with the browser handler.

For Mozilla Firefox browser:

  1. Open the Mozilla Firefox browser.

  2. Select MenuSettings and select General.

  3. Scroll to the Applications section.

  4. Locate mailto in the Content Type column.

  5. Select your preferred email client from the Action drop-down menu.

    Note

    Use the Use other option to configure an email client not listed in the menu.

  6. Change the system default account to match the email client selected in the Applications section.

For Safari browser

By default, Safari uses the built-in macOS email client. Use the Mail application settings to change the default email client for Safari.

  1. Open the Mail application on macOS.

  2. Go to MailSettings and General.

  3. Select your preferred email client from the Default email reader drop-down menu.