Application Control can work with a reputation managing source such as TIE server or Global Threat Intelligence file reputation service to fetch reputation information of files and certificates.
Based on information fetched from the reputation source, application, and executable files in the inventory are sorted into trusted, malicious, and unknown categories.
Manage the unclassified application in your environment to reduce the number of unknown applications. This list typically includes all unknown applications, and can be considered as greylist for your enterprise. The goal is to minimize risk and achieve 95% classification by removing or reclassifying unknown files and applications. Review and process greylist routinely to keep it to a minimum size.
Run GetClean on endpoints with a high number of unknown files. The GetClean utility submits files for analysis to Trellix Labs where they are verified and classified automatically and correctly.
Reclassify, internally developed, recognized, or trusted (from a reputed vendor or signed by a credible certificate) files that are currently in the unknown list.
If the TIE server is configured in your server, reset the files reputation on the TIE Reputationspage. When resetting the reputation for a signed file, you must set the reputation for the file's certificate to Unknown to allow the overridden reputation to be used. For more information, see the Trellix Threat Intelligence Exchange (TIE) Product Guide for your version of the software.
If the TIE server is unavailable, change the Enterprise Trust level or Reputation by Application Control of the file to Trusted.
Enable the automatic response Bad Binary has been detected in Enterprise from the Menu → Automation → Automatic Responses page.
For Known Malicious and Might be Malicious files or certificates encountered in your environment, the software generates Malicious File Found events that are displayed on the Menu → Reporting → Threat Event Log page. The Bad Binary has been detected in Enterprise automatic response is preconfigured in Application Control but is disabled by default. Make sure that the mail server for your enterprise is configured on the ePO - On-premconsole. For more information about how to set up an email server, see Trellix ePolicy Orchestrator - On-premises Product Guide.
Review the Solidcore: Inventory dashboard regularly to track and monitor inventory status for your environment.
Designate a base image for your enterprise to create an approved repository of known applications, including internally developed, recognized, or trusted applications. This makes management of desktop systems easier by verifying the corporate applications. Here are high-level steps to follow:
Validate and review all applications on a system.
Run GetClean on the system to classify all unknown applications on the system.
Set the base image on the approved system by using the Mark Trusted option.
Adding all binaries from the trusted system to your policy using Attr (auth by name) or Auth (auth by checksum) is not needed. This could cause performance issues on your clients. Solidification of a system with GTI/TIE reputation allows everything known with good reputation to run on your system.