File and certificate overrides tabs

Prev Next

View or change the current reputation information for files and certificates to better control what is allowed or blocked in your environment.

File Overrides tab

Option

Definition

Custom

Search for files using a custom filter. You can use one of the default filters, or create your own:

  • None — Leave the default values to filter your search.

  • Malicious files — Lists files with a malicious reputation. It includes files whose reputation is Known Malicious, Might be Malicious, and Most Likely Malicious.

  • Missing names — Lists files that don't have a name assigned to them.

  • Unknown files — Lists files that don't have a reputation assigned to it yet.

  • Add... — Create your own custom search filter to view specific rows of data. Click Add... to specify the search criteria to use. The custom filter is named "Unsaved". Click the right arrow next to the Unsaved label, then click Edit to name the custom search filter.

Quick find

Search for a specific file name or type of file. You can use search characters * or ?.

Show selected rows

Lists only those files that are selected.

All File Names

Lists the files and their details. Selecting a column heading sorts the list by that information.

Selecting a column heading

Select a column heading to sort the information by that type of information. When sorting by any type of reputation, for example by enterprise or Trellix Global Threat Intelligence reputation, the files are listed in this order:

  • Trusted Installer score

  • Known Trusted

  • Most Likely Trusted

  • Unknown

  • Most Likely Malicious

  • Known Malicious

  • Not Set

It lists only file reputation and not certificate reputation.

Caution

Sorting results appear by reputation value rather than alphabetically. For more information about the values, see Specifying the reputation as a number.

Selecting a file

Select a file to see details about it.

Actions

See File actions.



Certificate Overrides tab

Option

Definition

Custom

Search for certificates using a custom filter. You can use one of the default filters, or create your own:

  • None

  • Malicious Certificates — Lists certificates with a malicious reputation. This includes certificates whose reputation is Known Malicious, Might be Malicious, and Most Likely Malicious.

  • Unknown in GTI — Lists certificates whose reputation is unknown in Trellix Global Threat Intelligence.

  • Add... — Create a custom search filter. Click Add... to specify the search criteria to use. The custom filter is named "Unsaved". Click the right arrow next to the Unsaved label, then click Edit to name the filter.

Quick find

Search for a specific certificate. You can use search characters * or ?.

Show selected rows

List only those certificates that are selected.

Selecting a column heading

Select a column heading to sort the information by that type of information. When sorting by any type of reputation, for example by enterprise or Trellix Global Threat Intelligence reputation, the certificates are listed in this order:

  • Known Trusted

  • Most Likely Trusted

  • Unknown

  • Most Likely Malicious

  • Known Malicious

  • Not Set

Caution

Sorting results appear by reputation value rather than alphabetically. For more information about the values, see Specifying the reputation as a number.

Selecting a certificate

Select a certificate to see details about it.

Actions

See Certificate actions.

Subject

Shows information for the selected certificate.

Enterprise Reputation

It shows the enterprise reputation as it appears in TIE. This reputation that might be present or not. If it is not present, it means that it is not present in TIE environment.

GTI Reputation

Trellix Global Threat Intelligence is the main reputation source that TIE uses.

GTI certificate revocation

To be added.