Smart SOAR Integration

D3 and Trellix have joined forces to combine the Trellix suite with D3 Smart SOAR for automated incident response and silo-free investigations. The joint solution enables automated response to any alarm through D3’s codeless playbooks. Smart SOAR aggregates data and orchestrates actions across Trellix tools, creating a unified security operations hub.

Trellix (McAfee) Integration
Integration Capabilities
Trellix ePolicy Orchestrator Smart SOAR can orchestrate dozens of endpoint protection actions in Trellix ePO, including scanning endpoints, ingesting threat events, and updating policies.
Trellix Enterprise Security Manager Smart SOAR connects with Trellix ESM to provide well-informed incident response and investigation management to SIEM alarms. Smart SOAR ingests alarms as well as queries Trellix ESM for related events and contextual data.
Trellix Intelligent Sandbox Smart SOAR can detonate suspicious URLs in Trellix Intelligent Sandbox and ingest the results into incident reports.
Trellix Network Security D3 integrates with Trellix Network Security to quarantine hosts.

Key Use Cases

#1: Alarm Enrichment and Response

By combining Trellix ESM for threat detection with D3 Smart SOAR for incident enrichment and response, you can automatically escalate real threats to incident status in Smart SOAR and assess their criticality through data enrichment and MITRE ATT&CK matrix correlation. Smart SOAR can then trigger an automated response playbook or guide human analysts efficiently through manual steps, all within a single window.

Trellix (McAfee) Integration

#2: Complex Investigations Made Easy

To carry out a post-incident investigation with Trellix products and Smart SOAR, analysts can use prebuilt commands in Smart SOAR to rapidly gather alarm details, event logs, statuses, and other data from a range of Trellix products. Similar commands are available for other tools, giving investigators a centralized console for complex, end-to-end incident investigations.

Trellix (McAfee) Integration

Meet Our Friends

Our Connected SOAR Security Alliance brings hundreds of vendors together, allowing customers to benefit from our deep industry relationships and fully vendor-agnostic, independent SOAR platform.

X Trellix (McAfee) Integration

Get Started with D3 Security

One platform to stop alert overwhelm. Transform how your security team works, by focusing its resources on real threats.