• Last Updated
    Aug 29, 2025
  • Version
    1.1.0
  • Compatibility
    ThreatQ versions >= 4.0.0
  • Trellix EX Operation

    ThreatQuotient

    Overview

    The ThreatQuotient for Trellix EX Operation allows you to search for emails alerts in a Trellix EX appliance that contains specific indicators. If any alerts are returned, the data and indicators are parsed and listed in the ThreatQ UI.

    The operation provides the following action:

    • Search for Alerts - submits data to Trellix EX and returns matching alerts.
    • Search for Indicators - searches for Trellix EX alerts containing Malware or URL/Filename indicators. 

    The operation is compatible with the following object types:

    • Indicators (Email Address, Filename, MD5, URL)
    • Malware

    Note:  The Trellix EX operation replaces the FireEye EX operation as of version 1.1.0.

    Copyright © 2025, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy