# authorship: generated by API Evangelist tooling. Stamped 2026-08-18 # on the file's own generator header (roadmap#64). An unmarked file is # NOT assumed to be ours -- absence of evidence was never stamped. method: generated vocabulary: name: Trellix Vocabulary description: >- Domain vocabulary for the Trellix cybersecurity platform covering XDR, endpoint detection and response, threat intelligence, security operations, and enterprise security management concepts. version: 1.0.0 created: '2026-05-03' modified: '2026-05-03' tags: - Cybersecurity - Endpoint Security - Threat Detection - XDR terms: - term: XDR definition: >- Extended Detection and Response — a security platform that unifies data from multiple security layers (endpoints, networks, cloud, email) to provide comprehensive threat detection, investigation, and response. related: - EDR - SIEM - SOAR - term: EDR definition: >- Endpoint Detection and Response — technology that continuously monitors endpoints to detect, investigate, and respond to advanced threats and suspicious behaviors. related: - XDR - Threat Hunting - term: ePO definition: >- ePolicy Orchestrator — Trellix's centralized security management platform that provides policy enforcement, asset management, and reporting across the endpoint security ecosystem. related: - Security Management - Policy Orchestration - term: Threat definition: >- A confirmed or suspected malicious entity (malware, ransomware, exploit) detected on an endpoint by the Trellix security platform. related: - Detection - Malware - Threat Intelligence - term: Detection definition: >- A security finding generated by Trellix EDR when suspicious or malicious behavior is observed on an endpoint. related: - Threat - Alert - term: Alert definition: >- A notification generated by the Trellix platform requiring analyst attention, typically triggered by one or more detections. related: - Detection - Triage - term: Reaction definition: >- An automated or manual response action taken by the EDR platform in response to a threat, such as endpoint isolation, process termination, or file quarantine. related: - Response Action - Endpoint Isolation - term: Endpoint Isolation definition: >- A response action that disconnects a compromised endpoint from the network while maintaining management connectivity for investigation and remediation. related: - Reaction - Incident Response - term: Threat Hunting definition: >- Proactive search for indicators of compromise (IOCs) and attacker techniques across endpoints using queries and searches in the EDR platform. related: - EDR - IOC - term: IOC definition: >- Indicator of Compromise — evidence that a system has been breached, including file hashes, IP addresses, domains, registry keys, and behavioral patterns. related: - Threat Hunting - Detection - term: DXL definition: >- Data Exchange Layer — Trellix's messaging fabric enabling real-time communication and intelligence sharing between security tools. related: - TIE - Integration - term: TIE definition: >- Threat Intelligence Exchange — Trellix service that acts as a reputation broker, enabling real-time sharing of threat intelligence via DXL. related: - DXL - Threat Intelligence - term: MVISION definition: >- The cloud-delivered security platform from Trellix (formerly McAfee MVISION), now integrated into the Trellix product family providing cloud-native XDR. related: - XDR - Cloud Security - term: Response Action definition: >- A remediation operation executed on a managed device through ePO or EDR, such as quarantine, antivirus scan, policy update, or software deployment. related: - Reaction - Endpoint Management - term: Tag definition: >- A label applied to a device or group in ePO for organizational classification and policy targeting purposes. related: - Device Group - Policy Orchestration