Based on the settings in the TIE server policies, allow, block, or require user action for the file and certificate reputations used in your environment. You can fine-tune what is allowed or blocked by overriding default reputation settings for specific files and certificates.
File and certificate reputations are added to the TIE server database in four ways.
Running the TIE client module Threat Prevention or Endpoint Security Adaptive Threat Protection 10.5.
Intelligent Sandbox and McAfee Web Gateway send reputation information over the Trellix DXL framework and is added to the database.
External Reputation provider through OpenDXL.
Manually import files or certificates to the database.