Threat Intelligence Exchange functions differently, depending on whether it is communicating with TIE:
Threat Intelligence Exchange with TIE server enables you to control file reputation at a local level, in your environment. You decide which files can run and which are blocked, and the Trellix DXL shares the information immediately throughout your environment.
If the TIE server isn't present and the system isn't connected to the Internet, Threat Intelligence Exchange determines the file reputation using the JTI content (Threat Intelligence Exchange module content) for signed applications.
If the TIE server and Trellix DXL are present, Threat Intelligence Exchange and the server communicate file reputation information. The Trellix DXL framework immediately passes that information to managed endpoints. It also shares information with other Trellix products that access the Trellix DXL, such as Trellix Enterprise Security Manager and Trellix Intrusion Prevention System.