Trellix Endpoint Security Operations
Unified capability for SOC analysts and endpoint security engineers to detect, investigate, hunt, and respond to endpoint threats using Trellix EDR and ePO SaaS. Combines threat detection, alert investigation, real-time search, device management, and automated response actions for comprehensive endpoint security operations.
What You Can Do
MCP Tools
edr-list-threats
List threats detected by Trellix EDR for incident investigation and triage.
edr-list-detections
List endpoint detections from EDR for threat hunting and analysis.
edr-list-alerts
List security alerts from EDR for SOC triage and prioritization.
edr-create-search
Create a real-time search across endpoints to hunt for indicators of compromise.
edr-create-reaction
Execute an EDR response reaction on an endpoint (isolate, collect artifacts, terminate process).
epo-list-devices
List managed endpoint devices from ePO SaaS for asset inventory and status checks.
epo-list-events
List threat events from ePO SaaS for incident correlation and reporting.
epo-execute-query
Execute a saved ePO query for security reporting and compliance checks.
epo-create-response-action
Create an ePO response action on a managed device (quarantine, run scan, apply policy).