You can build file prevalence to determine how often unknown files are seen in your environment.
You can see what is running in your environment and add file and certificate reputation information to the TIE server database. This information also populates the graphs and dashboards in Trellix ePO - On-prem where you view detailed reputation information about files and certificates.
To get started, configure Adaptive Threat Protection settings on a few systems in your environment. The settings determine:
When a file or certificate with a specific reputation is allowed to run on a system
When a file or certificate is blocked
When an application is contained
When or if users are prompted for what to do
When a file is submitted to Sandbox server for further analysis
While building file prevalence, you can enable Observe mode on client systems. File and certificate reputations are added to the database and Would Block, Would Clean, and Would Contain events are generated, but no action is taken. You can see what Adaptive Threat Protection blocks, allows, or contains if the settings were enforced.