Skip to main content

Trellix HX

Trellix HX (formerly FireEye HX) is an advanced endpoint detection and response (EDR) platform that provides comprehensive threat hunting, investigation, and incident response capabilities across enterprise endpoints. As a leading endpoint security solution, Trellix HX enables security teams to detect, analyze, and respond to advanced persistent threats (APTs), malware infections, ransomware attacks, and sophisticated cyber threats in real-time.

CategoryEDR
DirectionQuery source
Sign-inUsername and Password
Query languagesSTIX
Websitetrellix.com

Before you start​

Huntbase signs in to Trellix HX with Username and Password. Create the credential in Trellix HX first, then keep it to hand for the Connect step.

  1. Sign in to the Endpoint Security (HX) web UI as an administrator.
  2. Go to Admin › Appliance Settings › User Accounts and add a new local user account with the api_analyst role. Don't reuse the built-in api_analyst account.
  3. Copy the new account's username and password.

Permissions:

  • api_analyst
Watch out for
  • HX allows at most 15 searches at a time. If new searches fail, delete existing searches in HX.
  • Each search returns results from at most 1,000 hosts per host set, taking the hosts that respond first.

For the vendor's own instructions, see Creating an HX API user account (Google SecOps guide).

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Trellix HX​

  1. Go to Connections and click New connection, or click New connection on the Trellix HX product page.
  2. On Product, pick Trellix HX and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Trellix HX lives:

FieldRequiredNotes
Server AddressYesThe hostname or IP address of your HX appliance.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 3000.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Credentials​

The only Method is Username and Password. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
UsernameYesUsername with access to the search API. Secret — not shown again after you save it.
PasswordYesPassword of the user with access to the search API. Secret — not shown again after you save it.

Query it​

Once connected, Trellix HX can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​