Enhance your threat intelligence and detection platform by enabling an external reputation provider in your environment through OpenDXL.
Make sure you have a DXL client provisioned in your local environment.
For details and troubleshooting about OpenDXL, visit the OpenDXL website.
If the endpoint doesn’t detect a match from other reputation providers, it can allow or block files based on the trust level assigned to the provider as a fallback rule.
Note
This feature supports only the file reputation and doesn't support the certificate reputation.
Select Menu → Server Settings → DXL Topic Authorization, then click Edit.
From the Topic Group list, select TIE Server External Reputation Provider Event → Actions → Restrict Send Certificates.
You are redirected to a window with all ePO - On-prem managed client certificates.
On the window, you have a list of the ePO - On-prem managed client certificates. Choose External Reputation Provider certificate.
Select the certificate, then click OK to allow the TIE server to receive events from the external provider.
Navigate to Policy Catalog → Trellix Threat Intelligence Exchange Management x.x.x, select a policy and click Edit.
Enable the External Reputation Provider. Click Save.
The OpenDXL integration can now publish external reputation events into the TIE Server. The recommended workflow is:
Check if TIE server can provide a definitive reputation for the file from any other provider.
If there is no reputation available for the file at the moment, publish an External Reputation event.
For more information and guidance, see python documents.