01ATTACK STAGEWhat is happening, and why
STAGE 01 · INITIAL ACCESSInitial accessSupplier engineering lure
WHAT'S HAPPENINGA convincing supplier update reaches an engineer through email and collaboration tools.
STAGE OBJECTIVEReach a trusted user through a convincing supplier message and create an initial path into the organisation.
ATTACK SEQUENCE⌄
- 01
Message arrivesA convincing supplier email reaches a procurement mailbox carrying a weaponised document and a link.
- 02
Content inspectedAttachment, URL and sender are examined before the message is allowed to reach the user.
- 03
Campaign context addedThreat intelligence connects the artefacts to a wider campaign rather than treating them as isolated.
02ATTACK ACTIVITYThe live signal and current environment activity
SIGNAL
!SIGNALSIGNAL
A supplier-branded attachment exhibits evasive behaviour.
03TRELLIX PLATFORMPrevention, coverage and outcome
OUTCOMEMalicious content observed
HOW TRELLIX PREVENTS OR RESPONDSTrellix Email Security: Inspects message content, attachments and URLs at the boundary, before a user can act on them. · IVX for Collaboration Platforms: Detonates the attachment in an isolated environment to reach a verdict on an unknown file. · Private GTI: Enriches sender, URL and file reputation from local and global intelligence.⌄
04VISIBILITY & EVIDENCEWhat Trellix can prove and investigate
WHAT TRELLIX SEESMessage headers, attachment hashes, URL reputation, user interaction and campaign relationships.
INVESTIGATION CONTEXTEmail Security and inspect the file before it reaches operational systems.
WHAT TRELLIX COLLECTS02 collected⌄
EMAIL
Supplier message · headers and URLsSender, routing, attachment hash and link reputation for the delivered message.
FILE
Weaponised attachmentThe malicious document, with its verdict from the .