Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Trellix Endpoint Security Connector Guide

Prev Next

Trellix Endpoint Security provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and analyze IT security risks. The Balbix integration with Trellix Endpoint Security ingests IT Infrastructure assets and associated vulnerabilities discovered by Trellix Endpoint Security.

Balbix uses AI to aggregate, normalize, and deduplicate ingested data, combining it with information from your existing IT and cybersecurity tools. This creates a unified, up-to-date view of your entire asset inventory, including vulnerabilities and their business and operational context.

Balbix’s AI models analyze this consolidated data to deliver actionable insights, such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. These insights provide a comprehensive risk assessment for individual assets, asset groups, or your entire enterprise, empowering you to make more informed and effective security decisions.

Integration Summary

This table provides a summary of the Balbix integration for the Trellix Endpoint Security connector.

Integration Type

Fetch: An inbound API integration used to fetch IT Infrastructure assets, associated vulnerabilities and risk event details.

Types of Assets Fetched

Host devices (includes desktops, laptops).

Types of Data Fetched

Asset names, hardware information, interface information (MAC address, IP address), OS information​, BIOS information, system information, software information, agent information, risk event information.

Prerequisites

To configure the Balbix connector, you must first create Trellix Endpoint Security API credentials with the appropriate permissions. These credentials are required for completing the configuration process.

Here are the steps you need to complete.

Get API Keys

Get API keys to access Trellix APIs. The bearer token should have tenantId and the required scope (tenantApikey).

Determine Scope

The Trellix Developer Portal provides the following key capabilities for customers and partners:

  • To set up access for API: To invoke Trellix APIs, a calling application needs a JWT access token. Customers and partners must first register a client type and assign scopes to create an access token using client credentials grant. As soon as the IAM client type is approved, customers and partners may generate client credentials which are used to generate JWT tokens.

  • Set up API Key: Trellix provides an API key to customers that must be provided on each API invocation.

  • Set up webhooks: An application may subscribe to a real-time feed of Trellix Endpoint Detection & Response events via webhooks. To accomplish this, the application needs to set up a REST endpoint and register it with the Trellix event hub. The webhook also needs to validate itself to Trellix by returning a signed response to a validation request.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Trellix Endpoint Security.

Step 1: Select the Connector

Start by selecting a connector using the steps outlined below:

  1. Go to Data Sources from the left navigation bar.

  2. In the Connectors table, click + Add Connector.

  3. Click Select a Connector to Configure to expand the window and view the list of available connectors.

  4. Click the + icon on the McAfee/Trellix Connector tile.

  5. Click Next to configure the connector.

Step 2: Configure the Connector

Configure the connector using the steps outlined below:

  1. Fill in the required configuration fields.

    Instance Name

    Trellix API Base URL

    Trellix API Client ID

    Trellix API Client Secret

    comment

    Asset Last Seen Days Filter

  2. After completing all the required fields, click Test Connection to verify the configuration.

Step 3: Schedule the Connector

Step 4: Review Connector Details

API Reference Documentation

To learn more about the Trellix Endpoint Security API, see the references listed below: