The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

File search

Prev Next

Search for files in the TIE database. The longer the module runs in your environment, the more populated the database becomes. A file is added to the database when the module requests information about it.

Option definitions

Option

Definition

Custom

Search for files using a custom filter. You can use one of the default filters, or create your own:

  • Malicious files — Lists files with a malicious reputation. This includes files whose reputation is Known Malicious, Might be Malicious, and Most Likely Malicious.

  • Missing names — Lists files that don't have name.

  • Unknown files — Lists files whose reputation is unknown.

  • Add... — Create your own custom search filter to view specific rows of data. Click Add... to specify the search criteria to use. The custom filter is named "Unsaved". Click the right arrow next to the Unsaved label, then click Edit to name the custom search filter.

Quick find

Search for a specific file name or type of file. You can use search characters * or ?.

Show selected rows

List only files that are selected.

Selecting a column heading

Select a column heading to sort the information. When sorting by any type of reputation, for example by Enterprise or Trellix Global Threat Intelligence reputation, the files are listed in this order:

  • Known Trusted

  • Most Likely Trusted

  • Unknown

  • Most Likely Malicious

  • Known Malicious

  • Not Set

Caution

Sorting results appear by reputation value rather than alphabetically. For more information about the values, see Specifying the reputation as a number.

Important

When TIE doesn't have information available for a file or its reputation, in the Reputation column appears "Not Available".

Selecting a file

Select a file to see its details.

Actions

See File actions.



TIE Reputations column headings

For each file, you have its name, company and product names, and its version. The information of its reputation and the reputation providers are displayed in different columns.

Option

Definition

Composite Reputation

Potential effective reputation score based on local reputation (if available) or an estimate based on other reputation scores (if the hash value isn't available at the endpoints).

Enterprise Reputation

File reputation assigned by the administrator.

Certificate Enterprise Reputation

Reputation assigned by the administrator to a certificate associated to a specific file.

Latest Local Reputation

Latest effective reputation used by the endpoint. If it's not available or informed, the server informs the next reputation based on its value and which provider informed it first.

Certificate GTI Reputation

Certificate reputation information provided by Trellix Global Threat Intelligence.

GTI Reputation

File reputation information provided by Trellix Global Threat Intelligence.

ATD Reputation

File reputation information provided by Intelligent Sandbox.

MWG Reputation

File reputation information provided by Web Gateway.

Latest Applied Rule

Latest detection rule applied at the endpoint based on file type.

External Reputation

File reputation information provided by an external provider.