The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Enable external reputation providers with OpenDXL

Prev Next

Enhance your threat intelligence and detection platform by enabling an external reputation provider in your environment through OpenDXL.

Make sure you have a Trellix DXL client provisioned in your local environment.

For details and troubleshooting about OpenDXL, visit the OpenDXL website.

If the endpoint doesn’t detect a match from other reputation providers, it can allow or block files based on the trust level assigned to the provider as a fallback rule.

Note

This feature supports only the file reputation and doesn't support the certificate reputation.

Task
  1. Select MenuServer SettingsDXL Topic Authorization, then click Edit.

  2. From the Topic Group list, select TIE Server External Reputation Provider EventActionsRestrict Send Certificates.

    You are redirected to a window with all Trellix ePO - On-prem managed client certificates.

  3. On the window, you have a list of the Trellix ePO - On-prem managed client certificates. Choose External Reputation Provider certificate.

  4. Select the certificate, then click OK to allow the TIE server to receive events from the external provider.

  5. Navigate to Policy CatalogTrellix Threat Intelligence Exchange Management x.x.x, select a policy and click Edit.

  6. Enable the External Reputation Provider. Click Save.

    The OpenDXL integration can now publish external reputation events into the TIE Server. The recommended workflow is:

    1. Check if TIE server can provide a definitive reputation for the file from any other provider.

    2. If there is no reputation available for the file at the moment, publish an External Reputation event.

    For more information and guidance, see python documents.