01ATTACK STAGEWhat is happening, and why
STAGE 01 · SHARED OBJECTShared objectWeaponised file in collaboration chat
WHAT'S HAPPENINGA supplier account shares an urgent invoice in a project channel.
STAGE OBJECTIVEReach a trusted user through a convincing supplier message and create an initial path into the organisation.
ATTACK SEQUENCE⌄
- 01
Message arrivesA convincing supplier email reaches a procurement mailbox carrying a weaponised document and a link.
- 02
Content inspectedAttachment, URL and sender are examined before the message is allowed to reach the user.
- 03
Campaign context addedThreat intelligence connects the artefacts to a wider campaign rather than treating them as isolated.
02ATTACK ACTIVITYThe live signal and current environment activity
SIGNAL
!SIGNALSIGNAL
An unknown document enters a trusted collaboration channel.
03TRELLIX PLATFORMPrevention, coverage and outcome
OUTCOMEObject inspected
HOW TRELLIX PREVENTS OR RESPONDSTrellix Email Security: Inspects message content, attachments and URLs at the boundary, before a user can act on them. · IVX for Collaboration Platforms: Detonates the attachment in an isolated environment to reach a verdict on an unknown file. · Private GTI: Enriches sender, URL and file reputation from local and global intelligence.⌄
04VISIBILITY & EVIDENCEWhat Trellix can prove and investigate
WHAT TRELLIX SEESMessage headers, attachment hashes, URL reputation, user interaction and campaign relationships.
INVESTIGATION CONTEXT for Collaboration Platforms continuously inspects shared files and links.
WHAT TRELLIX COLLECTS02 collected⌄
EMAIL
Supplier message · headers and URLsSender, routing, attachment hash and link reputation for the delivered message.
FILE
Weaponised attachmentThe malicious document, with its verdict from the .