Trellix Endpoint Security provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and analyze IT security risks. The Balbix integration with Trellix Endpoint Security ingests IT Infrastructure assets and associated vulnerabilities discovered by Trellix Endpoint Security.
Balbix uses AI to aggregate, normalize, and deduplicate ingested data, combining it with information from your existing IT and cybersecurity tools. This creates a unified, up-to-date view of your entire asset inventory, including vulnerabilities and their business and operational context.
Balbix’s AI models analyze this consolidated data to deliver actionable insights, such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. These insights provide a comprehensive risk assessment for individual assets, asset groups, or your entire enterprise, empowering you to make more informed and effective security decisions.
Integration Summary
This table provides a summary of the Balbix integration for the Trellix Endpoint Security connector.
Integration Type | Fetch: An inbound API integration used to fetch IT Infrastructure assets, associated vulnerabilities and risk event details. |
Types of Assets Fetched | Host devices (includes desktops, laptops). |
Types of Data Fetched | Asset names, hardware information, interface information (MAC address, IP address), OS information, BIOS information, system information, software information, agent information, risk event information. |
Prerequisites
To configure the Balbix connector, you must first create Trellix Endpoint Security API credentials with the appropriate permissions. These credentials are required for completing the configuration process.
Here are the steps you need to complete.
Get API Keys
Get API keys to access Trellix APIs. The bearer token should have tenantId and the required scope (tenantApikey).
Determine Scope
The Trellix Developer Portal provides the following key capabilities for customers and partners:
To set up access for API: To invoke Trellix APIs, a calling application needs a JWT access token. Customers and partners must first register a client type and assign scopes to create an access token using client credentials grant. As soon as the IAM client type is approved, customers and partners may generate client credentials which are used to generate JWT tokens.
Set up API Key: Trellix provides an API key to customers that must be provided on each API invocation.
Set up webhooks: An application may subscribe to a real-time feed of Trellix Endpoint Detection & Response events via webhooks. To accomplish this, the application needs to set up a REST endpoint and register it with the Trellix event hub. The webhook also needs to validate itself to Trellix by returning a signed response to a validation request.
Create and Configure the Connector
After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Trellix Endpoint Security.
Step 1: Select the Connector
Start by selecting a connector using the steps outlined below:
Go to Data Sources from the left navigation bar.
In the Connectors table, click + Add Connector.
Click Select a Connector to Configure to expand the window and view the list of available connectors.
Click the + icon on the McAfee/Trellix Connector tile.
Click Next to configure the connector.
Step 2: Configure the Connector
Configure the connector using the steps outlined below:
Fill in the required configuration fields.
.png)
.png)
Instance Name
.png)
Trellix API Base URL
.png)
Trellix API Client ID
.png)
Trellix API Client Secret
comment
.png)
Asset Last Seen Days Filter
After completing all the required fields, click Test Connection to verify the configuration.
Step 3: Schedule the Connector
Step 4: Review Connector Details
API Reference Documentation
To learn more about the Trellix Endpoint Security API, see the references listed below: