Adaptive Threat Protection uses the local reputation cache, the TIE server, and Trellix GTI for reputation information to determine how to handle files and processes on the client system. ATP uses rules to target live-off-the-land and fileless attacks, and enhanced remediation to roll back changes if attacks occur.
(Managed systems) The administrator configures ATP settings in Trellix ePO - On-prem and enforces it to the client system.
A user executes a file on the client system.
Adaptive Threat Protection checks the local reputation cache for the file.
If the file is not in the local reputation cache, Adaptive Threat Protection queries the TIE server, if available, for the reputation.
If the file is not in the TIE server database, the TIE server queries Trellix GTI for the reputation. If the TIE server is not available, ATP queries Trellix GTI for the reputation.
Depending on the file's reputation and ATP settings:
The file is allowed to run.
The file is cleaned.
The file is blocked.
The file is allowed to run in a container.
The user is prompted for the action to take.
For a process with a Known Trusted reputation, Adaptive Threat Protection rules determine the appropriate actions for the process. ATP monitors the process, its children, and ancestors for suspicious behavior, which can indicate a fileless attack, and blocks the process if needed. If the process reputation is Unknown (50) or lower, enhanced remediation backs up changes, and rolls back if the process exhibits malicious behavior.
Trellix GTI returns the latest file reputation information to the TIE server.
The TIE server updates the database and sends the updated reputation information to all ATP-enabled systems to immediately protect your environment.
ATP logs the details then, if managed, generates and sends an event to Trellix ePO - On-prem.

The way Adaptive Threat Protection functions depends on whether it communicates with the TIE server and whether it is connected to the Internet and connects directly to Trellix GTI.
If TIE server and Trellix DXL are present (Managed systems)
If the TIE server is present, Adaptive Threat Protection uses the Trellix DXL framework to share file and threat information instantly across the whole enterprise. You can see the specific system where a threat was first detected and where it went from there, and stop it immediately.
Adaptive Threat Protection with the TIE server enables you to control file reputation at a local level, in your environment. You decide which files can run and which are blocked, and the Trellix DXL shares the information immediately throughout your environment.
Note
To prevent business operations from being negatively impacted, Trellix might ignore some reputations in the TIE server, such as setting a Microsoft certificate to Known Malicious.
Adaptive Threat Protection and the TIE server communicate file reputation information and file metadata. The Trellix DXL framework immediately passes that information to managed endpoints. It also shares information with other Trellix products that access the Trellix DXL, such as Trellix Enterprise Security Manager and McAfee Network Security Platform.
.png)
If the TIE server and Trellix DXL are not present (Managed systems)
Adaptive Threat Protection communicates with Trellix GTI for file reputation information.
.png)
If the TIE server isn't present and the system isn't connected to the Internet, Adaptive Threat Protection determines the file reputation using ATP rules on the local system.
If TIE server and Trellix DXL are not present (Self-managed systems)
Adaptive Threat Protection communicates with Trellix GTI for file reputation information.

If the TIE server isn't present and the system isn't connected to the Internet, Adaptive Threat Protection determines the file reputation using ATP rules on the local system.