Endpoint workflow

Prev Next

The Solidcore client supports reputation-based execution on endpoints.

When the user executes a file, Application Control contacts the reputation source to fetch reputation information as follows:

  • If the TIE server is configured, the endpoint communicates with the server to fetch reputation for the executable file or all certificates associated with the file.

  • If the TIE server isn't installed or is unavailable, the endpoint communicates with the Trellix GTI server to fetch reputation for the executable file or all certificates associated with it.

Note

To verify if fetching reputation from TIE server or Trellix GTI server is enabled for an endpoint, review the value for the Reputation (TIE) or Reputation (GTI) property for the endpoint. To navigate to the property, click the row corresponding to the endpoint on the Systems page and click the Solidcore row in the Products tab.

  1. Check if an explicit ban rule exists for the file.

    • If yes, prevent file execution.

    • If no, verify the file and certificate reputation.

  2. Allow or block file execution based on reputation according to the defined reputation settings.

Application Control also uses defined rules and policies to determine file execution status.

GUID-6D1CFAED-6A45-46E4-AAC4-DBEAA0E07F39-low.png