File reputation is the data that comes from different reputation providers in the on-premises environment.
This is how the reputation of a file or certificate is obtained.
A user or system tries to run a file.
Trellix ENS checks the exclusions to determine whether to inspect the file or not.
Trellix ENS inspects the file and can't determine its validity and reputation.
The Threat Intelligence Exchange module inspects the file and gathers file and local system properties.
The module checks the local reputation cache for the file hash.
If the file hash is found, the module gets the file's reputation data from the cache.
If the file hash is not found in the local reputation cache, the module queries the TIE server. If the TIE server is not reachable, it queries with Trellix GTI for file reputation. If the hash is found, the module gets the reputation for that file hash.
If the file hash is not found in the TIE server database, the server queries Trellix GTI for the file hash reputation. Trellix GTI sends the available information, for example "unknown" or "malicious," and the server stores that information.
The module evaluates the following metadata to determine the file's reputation, plus all metadata sent, and uses the TIE Content rules to determine local reputation.
File and system properties
Reputation
The TIE server returns the file hash's enterprise age, prevalence data, and other data points to the client based on the data found. If the file is new to the environment, the server sets the flag to submit metadata on the response.
The client responds according to the settings on the system that is running the file and blocks or allows executing the file.
The module updates the server with the reputation information and whether the file is blocked or allowed. It also sends threat events to ePO - On-prem through the Trellix Agent.
The TIE server publishes the reputation change event for the file hash.