Trellix HX
Trellix HX (formerly FireEye HX) is an advanced endpoint detection and response (EDR) platform that provides comprehensive threat hunting, investigation, and incident response capabilities across enterprise endpoints. As a leading endpoint security solution, Trellix HX enables security teams to detect, analyze, and respond to advanced persistent threats (APTs), malware infections, ransomware attacks, and sophisticated cyber threats in real-time.
| Category | EDR |
| Direction | Query source |
| Sign-in | Username and Password |
| Query languages | STIX |
| Website | trellix.com |
Before you start
Huntbase signs in to Trellix HX with Username and Password. Create the credential in Trellix HX first, then keep it to hand for the Connect step.
- Sign in to the Endpoint Security (HX) web UI as an administrator.
- Go to Admin › Appliance Settings › User Accounts and add a new local user account with the
api_analystrole. Don't reuse the built-inapi_analystaccount. - Copy the new account's username and password.
Permissions:
api_analyst
- HX allows at most 15 searches at a time. If new searches fail, delete existing searches in HX.
- Each search returns results from at most 1,000 hosts per host set, taking the hosts that respond first.
For the vendor's own instructions, see Creating an HX API user account (Google SecOps guide).
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Trellix HX
- Go to Connections and click New connection, or click New connection on the Trellix HX product page.
- On Product, pick Trellix HX and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Trellix HX lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname or IP address of your HX appliance. |
| Port | Yes | Set the port number that is associated with the hostname or IP address. Defaults to 3000. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Credentials
The only Method is Username and Password. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Username | Yes | Username with access to the search API. Secret — not shown again after you save it. |
| Password | Yes | Password of the user with access to the search API. Secret — not shown again after you save it. |
Query it
Once connected, Trellix HX can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog