Use the Threat Intelligence Exchange policy to define rule assignments, define actions based on reputation threshold and configure message notifications.
Log on to the ePO - On-prem server as an administrator.
From the Policy Catalog page, select Endpoint Security Adaptive Threat Protection as the product, then Options as the category.
Click New Policy, type a name for the policy, then click OK.
Note
To edit the existing policy, click the name of the policy.
On the Policy Catalog page, click the policy that you created, then click Show Advanced.
In Adaptive Threat Protection, define these settings as required.
Enable Adaptive Threat Protection — Enables the Adaptive Threat Protection module.
Allow the Threat Intelligence Exchange server to collect anonymous diagnostic and usage data — Allows the TIE server to send anonymous file information to Trellix.
Use Trellix GTI file reputation if the Threat Intelligence Exchange server is not reachable — Gets file reputation information from the Global Threat Intelligence proxy if the TIE server is unavailable.
In Rule Assignment, define these settings as required.
Productivity — Assigns the Productivity rule group. Use this group for high-change systems with frequent installations and updates of trusted software.
Balanced — Assigns the Balanced rule group. Use this group for typical business systems with infrequent new software and changes.
Security — Assigns the Security rule group. Use this group for low-change systems, such as IT-managed systems and servers with tight control.
In Action Enforcement, define these settings.
Block when reputation threshold reaches
Clean when reputation threshold reaches
Click Save.