Launch the import wizard and select a STIX (Structured Threat Information eXpression) standard XML file or a CSV file to import file hashes in a wizard and to add a file reputation overrides to the TIE services database. Trellix TIE currently supports only STIX 1.x for threat intelligence imports.
You can generate CSV files by exporting TIE reputation tables. Add the columns for hash values, then use the Export Table task.
Important
Overriding file and certificate reputations not seen on the environment yet, files home brewed by the customer, or reputations from third party sources. We don't recommend that you import files or certificates with a matching Trellix GTI reputation.
Before you import a file, ensure it contains the following data, based on its file type:
STIX — At least one hash value (SHA1 Hash, MD5 Hash, and SHA256 Hash).
CSV — All File Names, and at least one hash value (SHA-256 Hash, SHA-1 Hash, and MD5 Hash).
The following example shows the required format for importing reputations from a CSV file.
All File Names
SHA-256 Hash
SHA-1 Hash
MD5 Hash
<filename>
<sha-256 hash>
<sha-1 hash>
<md5 hash>
Note
UTF-8 encoding is supported for CSV file imports.
In ePO - On-prem, select Menu → Systems → TIE Reputations.
On the File Overrides tab, click the Actions menu and then select Launch import wizard.
On the Select file tab, browse to the file location, whether for importing a STIX or a CSV file, then click Next.
Caution
When importing reputations, it is important that the file is in a supported format to avoid errors. If the file is corrupt or in an unsupported format, the import will fail with an error.
The Review details page displays the details of the imported file. For more information, see the Review details of STIX or CSV import.
For information about STIX, go to www.stix.mitre.org.
Note
TIE services doesn't support conditions.
On the Review details tab, select checkbox, then click Submit selected items.
On the Confirm action tab, select Reputation to import information, and add comment, then click Confirm.
File and certificate overrides are imported.