Launch import wizard

Prev Next

Launch the import wizard and select a STIX (Structured Threat Information eXpression) standard XML file or a CSV file to import file hashes in a wizard and to add a file reputation overrides to the TIE services database.

The STIX or the CSV file must have one hash value, minimum.

You can generate CSV files by exporting TIE reputation tables. Add the columns for hash values, then use the Export Table task.

Important

Overriding file and certificate reputations not seen on the environment yet, files home brewed by the customer, or reputations from third party sources. We don't recommend that you import files or certificates with a matching Trellix GTI reputation.

  1. In ePO - SaaS, select MenuSystemsTIE Reputations.

  2. On the File Overrides tab, click the Actions menu and then select Launch import wizard.

  3. On the Select file tab, browse to the file location, whether for importing a STIX or a CSV file, then click Next.

    For information about STIX, go to www.stix.mitre.org.

    Note

    TIE services doesn't support conditions.

  4. On the Review details tab, select checkbox, then click Submit selected items.

  5. On the Confirm action tab, select Reputation to import information, and add comment, then click Confirm.

File and certificate overrides are imported.