01ATTACK STAGEWhat is happening, and why
STAGE 01 · DELIVERYDeliveryWeaponised supplier email
WHAT'S HAPPENINGA procurement mailbox receives a convincing message containing a malicious document and link.
STAGE OBJECTIVEReach a trusted user through a convincing supplier message and create an initial path into the organisation.
ATTACK SEQUENCE⌄
- 01
Message arrivesA convincing supplier email reaches a procurement mailbox carrying a weaponised document and a link.
- 02
Content inspectedAttachment, URL and sender are examined before the message is allowed to reach the user.
- 03
Campaign context addedThreat intelligence connects the artefacts to a wider campaign rather than treating them as isolated.
02ATTACK ACTIVITYThe live signal and current environment activity
SIGNAL
!OBSERVEDSIGNAL
A procurement mailbox received a convincing message carrying a malicious document and link.
03TRELLIX PLATFORMPrevention, coverage and outcome
OUTCOMEThreat observed before user execution
HOW TRELLIX PREVENTS OR RESPONDSTrellix Email Security: Inspects message content, attachments and URLs at the boundary, before a user can act on them. · IVX for Collaboration Platforms: Detonates the attachment in an isolated environment to reach a verdict on an unknown file. · Private GTI: Enriches sender, URL and file reputation from local and global intelligence.⌄
04VISIBILITY & EVIDENCEWhat Trellix can prove and investigate
WHAT TRELLIX SEESMessage headers, attachment hashes, URL reputation, user interaction and campaign relationships.
INVESTIGATION CONTEXTEmail inspection and threat intelligence identify suspicious content and campaign relationships.
WHAT TRELLIX COLLECTS02 collected⌄
EMAIL
Supplier message · headers and URLsSender, routing, attachment hash and link reputation for the delivered message.
FILE
Weaponised attachmentThe malicious document, with its verdict from the .