When a file tries to run on a managed system, the TIE server stores and shares threat information based on file and certificate reputations that it receives from different reputation providers, on premise and in the cloud, and determines its reputation.
A file or certificate's reputation is determined as follows.
A user or system tries to run a file.
Trellix ENS Adaptive Threat Protection (ATP) inspects the file and is unable to determine its validity and reputation.
The client for Trellix ENS Adaptive Threat Protection (ATP) inspects the file and gathers file and local system properties of interest.
The module checks the local reputation cache for the file hash.
If the file hash is found, the module gets the file's prevalence and reputation data from the cache.
If the file hash is not found, the module queries the TIE server. If the hash is found, the module gets the prevalence data (and any available reputations) for that file hash.
If the file hash is not found in the TIE server database, the server queries Trellix GTI for the file hash reputation. Trellix GTI sends the available information, for example "unknown" or "malicious," and the server stores that information.
If sandboxing is enabled as a reputation provider, the file is identified as a candidate for submission.
The TIE server returns the file hash's enterprise age, prevalence data, and other data points to the client based on the data found. If the file is new to the environment, the server sets the flag to submit metadata on the response. Reputation response can include information from different providers other than Trellix GTI or Enterprise Overrides, for example, Web Gateway or Sandboxing.
The module evaluates the following metadata to determine the file's reputation, plus all metadata sent, and uses the TIE Content rules to determine local reputation.
File and system properties
Enterprise age and prevalence data
Reputation
The client responds according to the settings on the system that is running the file and blocks or allows executing the file.
The client updates the server with the reputation information defined by a set of TIE content rules, and whether the file is allowed or blocked. It also sends threat events to ePO - On-prem via the Trellix Agent.