When a file tries to run on a managed system, the TIE services store and share threat information based on file and certificate reputations that it receives from different reputation providers, on premise and in the cloud, and determines its reputation.
A file or certificate's reputation is determined as follows.
A user or system tries to run a file.
TI ENS inspects the file and is unable to determine its validity and reputation.
The client TI ENS inspects the file and gathers file and local system properties of interest.
The client checks the local reputation cache for the file hash.
If the file hash is found, the client gets the file's prevalence and reputation data from the cache.
If the file hash is not found, the client queries the TIE services. If the hash is found, the client gets the prevalence data (add any available reputations) for that file hash.
If the file hash is not found in the TIE services database, the service queries Trellix GTI for the file hash reputation. Trellix GTI sends available information, for example "unknown or "malicious" and service stores that information.
If Intelligent Sandbox, IVX or IVX Cloud (sandboxing) is enabled as a reputation provider, the file is identified as a candidate for submission.
The TIE services return the file hash's enterprise age, prevalence data, and other data points to the client based on the data found. If the file is new to the environment, the service sets the flag to submit metadata on the response.
The client evaluates the following metadata to determine the file's reputation, plus all metadata sent, and uses the TIE content rules to determine local reputation.
File and system storage
Reputation
The client responds according to the settings on the system that is runs the file and blocks or allows executing the file.
The client updates the TIE services with the reputation information defined by a set of TIE content rules, and whether the file is allowed or blocked. It also sends threat events to ePO - SaaS via the Trellix Agent.