File search

Prev Next

Search for files in the TIE services database. The longer the client runs in your environment, the more populated the database becomes. A file is added to the database when the client requests information about it.

Option definitions

Option

Definition

Custom

Search for files using a custom filter. You can use one of the default filters, or create your own:

  • Malicious files — Lists files with a malicious reputation. This includes files whose reputation is Known Malicious, Might be Malicious, and Most Likely Malicious.

  • Missing names — Lists files that don't have name.

  • Unknown files — Lists files whose reputation is unknown.

  • Add... — Create your own custom search filter to view specific rows of data. Click Add... to specify the search criteria to use. The custom filter is named "Unsaved". Click the right arrow next to the Unsaved label, then click Edit to name the custom search filter.

Quick find

Search for a specific file name or type of file. You can use search characters * or ?.

Show selected rows

List only files that are selected.

Selecting a column heading

Select a column heading to sort the information. When sorting by any type of reputation, for example by Enterprise or Trellix Global Threat Intelligence reputation, the files are listed in this order:

  • Known Trusted

  • Most Likely Trusted

  • Unknown

  • Most Likely Malicious

  • Known Malicious

  • Not Set

Caution

Sorting results appear by reputation value rather than alphabetically. For more information about the values, see Specifying the reputation as a number.

Important

When TIE doesn't have information available for a file or its reputation, in the reputation column appears "Not Available".

Selecting a file

Select a file to see its details.

Actions

See File actions.



TIE Reputations column headings

For each file, you have its name, company and product names, and its version. The information of its reputation and the reputation providers are displayed in different columns.

Option

Definition

Composite Reputation

Potential effective reputation score based on local reputation (if available) or an estimate based on other reputation scores (if the hash value isn't available at the endpoints).

Enterprise Reputation

File reputation assigned by the administrator.

Certificate Enterprise Reputation

Reputation assigned by the administrator to a certificate associated to a specific file.

Latest Local Reputation

Latest effective reputation used by the endpoint. If it's not available or informed, the service informs the next reputation based on its value and which provider informed it first.

Certificate GTI Reputation

Certificate reputation information provided by Trellix Global Threat Intelligence.

GTI Reputation

File reputation information provided by Trellix Global Threat Intelligence.

TIS Reputation

File reputation information provided by Intelligent Sandbox.

IVX Reputation

File reputation information provided by IVX.

IVX Cloud Reputation

File reputation information provided by IVX Cloud.

Latest Applied Rule

Latest detection rule applied at the endpoint based on file type.

External Reputation

File reputation information provided by an external provider.