Configure reputation-based workflows on Application Control endpoints.
Pane | Option | Definition |
|---|---|---|
What's reputation-based execution? | Opens a Trellix KnowledgeBase article that explains reputation-based execution. | |
Reputation | Use Trellix Threat Intelligence Exchange (TIE) server | Select to fetch reputation from the TIE server. This option is selected by default and comes into play if you have a TIE server installed in your setup. If this option is selected, reputation for files and certificates is fetched from the TIE server. The reputation values control execution at endpoints and are displayed on the Application Control pages on the ePO - On-prem console. The administrator can review the reputation values and make informed decisions for inventory items in the enterprise. |
TIE Enterprise Trust Level | Select to use TIE Enterprise as the exclusive source for file reputation. When this option is enabled, Application Control uses reputation information only from the TIE Enterprise server and does not use reputations from Trellix GTI or Intelligent Sandbox. This option allows organizations to rely exclusively on internally defined reputation intelligence from the TIE server when evaluating file execution on endpoints. | |
Use Trellix Global Threat Intelligence (Trellix GTI) | Select to fetch reputation from the Trellix GTI server when the TIE server is unavailable or not installed. This option is selected by default. If this option is selected, reputation for files and certificates is fetched from the Trellix GTI server. The reputation values control execution at endpoints and are displayed on the Application Control pages on the ePO - On-prem console. The administrator can review the reputation values and make informed decisions for inventory items in the enterprise. | |
Reputation-Based Execution Settings | Allow files with | Select to define the file reputation levels for which to allow execution of files on the endpoint. For example, if you select the checkbox and then select Might be Trusted from the drop-down list, all files with Known Trusted, Most Likely Trusted, and Might be Trusted reputation are allowed to execute on the endpoints. Select this option when performing new installations. By default, the option is selected with the Most Likely Trusted reputation value. |
Ban files with | Select to define the file reputation levels for which to prevent execution of files on the endpoint. For example, if you select the checkbox and then select Might be Malicious from the drop-down list, all files with Might be Malicious, Most Likely Malicious, and Known Malicious reputation are prevented from executing on the endpoints. Select this option when performing new installations and upgrades. By default, the option is selected with the Might be Malicious reputation value. | |
Advanced Threat Defense (ATD) Settings | Send files with | Select this option to automatically send files with the specified reputation levels to ATD for further analysis. We recommend you select this option if ATD is available in your setup. If you select the checkbox and then select Unknown from the drop-down list, all files with Unknown, Might be Malicious, Most Likely Malicious, and Might be Trusted reputation are sent to ATD. This option is not selected by default. |
Limit file size to | Select to specify the size of the files to send to ATD for analysis. Select the checkbox and specify the file size (in MB) in the text box. Possible values are between 1 MB to 10 MB. This option is not selected by default. | |