Configure the files that need to be uploaded to IVX for execution and analysis.
Verify that sandboxing is enabled and configured correctly in ePO - On-prem on the Policy Catalog page through health checks.
Important
Before integrating IVX with Trellix TIE, the user needs to ensure that a cluster is configured on IVX and the node role is set to broker, even if there is only a single IVX server that requires integration. For more information about configuring an IVX cluster, see IVX Administration Guide.
If you select multiple files, the portable executable (PE) files are prioritized and sent to IVX sandboxing.
In ePO - On-prem, select Policy Catalog → Threat Intelligence Exchange.
Click TIE Settings, then edit My Default Policy Settings.
Select Sandboxing. In IVX, enable the service and configure the server list (credentials, IP address) and the connection settings.
Click (+) to select multiple servers.
Note
By default, Enforce Certificate Validations is enabled to avoid MiTM attacks
Click Save when you are finished.
TIE server submits the files selected to IVX for further analysis.