The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Monitoring and making adjustments

Prev Next

If a file's reputation is unknown, you can submit it to Intelligent Sandbox for further analysis. Use the TIE server settings to specify which files you submit.

Use the ePO - On-prem dashboards and event views to see the files and certificates that are allowed or blocked based on the policies.

You can view detailed information by endpoint, file, rule, or certificate, and quickly see the number of items identified and the actions taken. You can drill down by clicking an item, and adjust the reputation settings for specific files or certificates so that the appropriate action is taken.

For example, if a file's reputation is unknown but you know it's a trusted file, you can change its reputation to trusted. The application is then allowed to run in your environment without being blocked or prompting the user for action. You might change the reputation for internal or custom files used in your environment.

  • Use the TIE Reputations feature to search for a specific file or certificate name. You can view details about the file or certificate, including the company name, SHA-1 and SHA-256 hash values, MD5, description, and Trellix GTI information. For files, you can also access VirusTotal data directly from the TIE Reputations details page to see additional information (see About VirusTotal).

  • Use the Reporting Dashboard page to see several types of reputation information at once. You can view the number of new files seen in your environment in the last week, files by reputation, files whose reputations recently changed, systems that recently ran new files, and more. Clicking an item in the dashboard displays detailed information.

  • If you identified a harmful or suspicious file, you can quickly see which systems ran the file and might be compromised.

  • Change the reputation of a file or certificate as needed for your environment. The information is immediately updated in the database and sent to all devices in your environment. Files and certificates are blocked or allowed based on their reputation.

    If you're not sure what to do about a specific file or certificate, you can block it from running while you learn more about it. Unlike a VirusScan Enterprise Clean action, which might delete the file, blocking keeps the file in place but doesn't allow it to run. The file stays intact while you research it.

  • Import file or certificate reputations into the database to allow or block specific files or certificates based on other reputations sources. This allows you to use the imported settings for specific files and certificates without having to set them individually on the server.

  • The Composite Reputation column on TIE Reputations page shows the most prevalent reputation and its provider.

  • The Latest Applied Rule column on the TIE Reputations page shows and tracks reputation information based on the latest detection rule applied for each file at the endpoint.

    You can customize this page by selecting ActionsChoose Columns. See the product documentation for Trellix Threat Intelligence Exchange.