Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. ATI may provide threat intelligence that tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) Cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.
Threat intelligence for malware object alerts
The following diagram illustrates the types of threat intelligence that ATI provides for malware object alerts, which are triggered by MD5 checksum matches on appliances:

ATI for standalone Email Security - Server Appliances
When an MD5 checksum match triggers a malware object alert on an appliance in standalone mode, the appliance fetches threat intelligence from the DTI Cloud, stores the additional information in its database, and displays the threat intelligence with the alert details.
ATI support on a standalone appliance has the following requirements:
The Email Security - Server appliance must have a two-way sharing license installed.
The Email Security - Server appliance must have the ATI feature enabled. This is the default setting.
ATI for managed Email Security - Server appliances
For malware object alerts triggered on managed Email Security - Server appliances, the Central Management System appliance aggregates the MD5 checksums that trigger the alerts, fetches threat intelligence from the DTI Cloud, stores the information in the Central Management System database only, and displays the threat intelligence with the alert details for the managed appliances.
Note
For managed Email Security - Serverappliances, you configure ATI settings from the CLI of the Central Management System appliance.
After you add an ATI-enabled appliance to the management domain of a Central Management System appliance, the Alerts tab of the managed appliance continues to show threat intelligence that the appliance obtained while it was operating in standalone mode. Subsequently triggered ATI alerts, however, are visible only on the Central Management System appliance.
After you remove an appliance from the management domain of a Central Management System appliance, the Email Security - Server appliance queries the DTI server for ATI data when new ATI alerts trigger on the appliance.