The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Building file prevalence using Observe mode

Prev Next

You can build file prevalence to determine how often unknown files are seen in your environment.

You can see what is running in your environment and add file and certificate reputation information to the TIE server database. This information also populates the graphs and dashboards in ePO - On-prem where you view detailed reputation information about files and certificates.

To get started, configure Adaptive Threat Protection settings on a few systems in your environment. The settings determine:

  • When a file or certificate with a specific reputation is allowed to run on a system

  • When a file or certificate is blocked

  • When an application is contained

  • When or if users are prompted for what to do

  • When a file is submitted to Sandbox server for further analysis

While building file prevalence, you can enable Observe mode on client systems. File and certificate reputations are added to the database and Would Block, Would Clean, and Would Contain events are generated, but no action is taken. You can see what Adaptive Threat Protection blocks, allows, or contains if the settings were enforced.