Managing threat reputations on the TIE services database

Prev Next

Based on the settings in the TIE services policies, allow, block, or require user action for the file and certificate reputations used in your environment. You can fine-tune what is allowed or blocked by overriding default reputation settings for specific files and certificates.

You can add file and certificate reputations to the TIE services database running the client and Intelligent Sandbox these send reputation information over the Trellix DXL framework, and manually import reputations to the database.

File and certificate reputations are added to the TIE services database in four ways.

  • Running the client TI ENS.

  • Intelligent Sandbox, IVX or IVX Cloud sends reputation information over the Trellix DXL framework and is added to the database.

  • External reputation provider through OpenDXL.

  • Manually import files or certificates to the database.