01ATTACK STAGEWhat is happening, and why
STAGE 01 · UPDATE RECEIVEDUpdate receivedCompromised supplier package
WHAT'S HAPPENINGA signed-looking maintenance package arrives through an established supplier process.
STAGE OBJECTIVEReach a trusted user through a convincing supplier message and create an initial path into the organisation.
ATTACK SEQUENCE⌄
- 01
Message arrivesA convincing supplier email reaches a procurement mailbox carrying a weaponised document and a link.
- 02
Content inspectedAttachment, URL and sender are examined before the message is allowed to reach the user.
- 03
Campaign context addedThreat intelligence connects the artefacts to a wider campaign rather than treating them as isolated.
02ATTACK ACTIVITYThe live signal and current environment activity
SIGNAL
!SIGNALSIGNAL
A trusted supplier package contains an unusual embedded object.
03TRELLIX PLATFORMPrevention, coverage and outcome
OUTCOMEPackage placed under inspection
HOW TRELLIX PREVENTS OR RESPONDSTrellix Email Security: Inspects message content, attachments and URLs at the boundary, before a user can act on them. · IVX for Collaboration Platforms: Detonates the attachment in an isolated environment to reach a verdict on an unknown file. · Private GTI: Enriches sender, URL and file reputation from local and global intelligence.⌄
04VISIBILITY & EVIDENCEWhat Trellix can prove and investigate
WHAT TRELLIX SEESMessage headers, attachment hashes, URL reputation, user interaction and campaign relationships.
INVESTIGATION CONTEXTEmail and collaboration inspection submit the object for reputation and behavioural analysis.
WHAT TRELLIX COLLECTS02 collected⌄
EMAIL
Supplier message · headers and URLsSender, routing, attachment hash and link reputation for the delivered message.
FILE
Weaponised attachmentThe malicious document, with its verdict from the .