The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Monitoring and making adjustments

Prev Next

You can see files and certificates that are blocked, allowed, or contained based on the policies using dashboards and event views. If you have TIE server in your environment, you can use the TIE server extension in Trellix ePO - On-prem to view and change reputations.

You can view detailed information by endpoint, file, rule, or certificate, and quickly see the number of items identified and the actions taken. You can drill down by clicking an item, and adjust the reputation settings for specific files or certificates so that the appropriate action is taken.

For example, if a file's default reputation is suspicious or unknown but you know it's a trusted file, you can either exclude it from scanning or change its reputation to trusted. The application is then allowed to run in your environment without being blocked or prompting the user for action. You might change the reputation for internal or custom files used in your environment.

  • Use the TIE Reputations feature to search for a specific file or certificate name. You can view details about the file or certificate, including the company name, SHA-1 and SHA-256 hash values, MD5, description, and Adaptive Threat Protection information. For files, you can also access VirusTotal data directly from the TIE Reputations details page to see additional information (see About VirusTotal).

  • Use the Reporting Dashboard page to see several types of reputation information at once. You can view the number of new files seen in your environment in the last week, files by reputation, files whose reputations recently changed, systems that recently ran new files, and more. Clicking an item in the dashboard displays detailed information.

  • If you identified a harmful or suspicious file, you can quickly see which systems ran the file and might be compromised.

  • Import file or certificate reputations into the database to allow or block specific files or certificates based on other reputation sources. This allows you to use the imported settings for specific files and certificates without having to set them individually on the server.

  • The Composite Reputation column on the TIE Reputations page shows the most prevalent reputation and its provider (TIE server 2.0 and later).

  • The Latest Applied Rule column on the TIE Reputations page shows and tracks reputation information based on the latest detection rule applied for each file at the endpoint.

    You can customize this page by selecting ActionsChoose Columns.

For more information, see the TIE server documentation.

You can also use the Trellix GetClean tool, which uses Trellix GTI to report on files that are unknown to Trellix Advanced Research Center, or falsely classified. Using GetClean, you can submit samples or metadata to Trellix Advanced Research Center for whitelisting by Trellix GTI.