Enhance your threat intelligence and detection platform by enabling an external reputation provider in your environment through OpenDXL.
Make sure you have a DXL client provisioned in your local environment.
For details and troubleshooting about OpenDXL, visit the OpenDXL website.
If the endpoint doesn’t detect a match from other reputation providers, it can allow or block files based on the trust level assigned to the provider as a fallback rule.
Note
This feature supports only the file reputation and doesn't support the certificate reputation.
For details about enabling OpenDXL on ePO - SaaS, see Trellix Data Exchange Layer Product Guide.
Select → → , then click Edit.
From the Topic Group list, select → → .
You are redirected to a window with all ePO - SaaS managed client certificates.
On the window, you have a list of the ePO - SaaS managed client certificates. Choose External Reputation Provider certificate.
Select the certificate, then click OK to allow the TIE server to receive events from the external provider.
Navigate to → , select a policy and click Edit.
Enable the External Reputation Provider. Click Save.
The OpenDXL integration can now publish external reputation events into the TIE Server. The recommended workflow is:
Check if TIE server can provide a definitive reputation for the file from any other provider.
If there is no reputation available for the file at the moment, publish an External Reputation event.
For more information and guidance, see python documents.