01ATTACK STAGEWhat is happening, and why
STAGE 01 · RISK SIGNALRisk signalSensitive file shared into collaboration
WHAT'S HAPPENINGA trusted analyst receives a restricted citizen-services export through a collaboration workspace.
STAGE OBJECTIVEReach a trusted user through a convincing supplier message and create an initial path into the organisation.
ATTACK SEQUENCE⌄
- 01
Message arrivesA convincing supplier email reaches a procurement mailbox carrying a weaponised document and a link.
- 02
Content inspectedAttachment, URL and sender are examined before the message is allowed to reach the user.
- 03
Campaign context addedThreat intelligence connects the artefacts to a wider campaign rather than treating them as isolated.
02ATTACK ACTIVITYThe live signal and current environment activity
SIGNAL
!SIGNALSIGNAL
Restricted records are identified in a collaboration channel.
03TRELLIX PLATFORMPrevention, coverage and outcome
OUTCOMESensitive content identified
HOW TRELLIX PREVENTS OR RESPONDSTrellix Email Security: Inspects message content, attachments and URLs at the boundary, before a user can act on them. · IVX for Collaboration Platforms: Detonates the attachment in an isolated environment to reach a verdict on an unknown file. · Private GTI: Enriches sender, URL and file reputation from local and global intelligence.⌄
04VISIBILITY & EVIDENCEWhat Trellix can prove and investigate
WHAT TRELLIX SEESMessage headers, attachment hashes, URL reputation, user interaction and campaign relationships.
INVESTIGATION CONTEXT classification identifies regulated information before it is redistributed.
WHAT TRELLIX COLLECTS02 collected⌄
EMAIL
Supplier message · headers and URLsSender, routing, attachment hash and link reputation for the delivered message.
FILE
Weaponised attachmentThe malicious document, with its verdict from the .