Trellix GTI uses heuristics file reputation to check for suspicious files through on-access scanning and on-demand scanning.
You can enable Trellix GTI protection on standalone systems and systems managed by ePO - On-prem or by ePO - SaaS.
When an executable file is accessed by a user, or a manual or automated scan of a workstation or server is performed, files are checked against the Trellix DAT files to determine if they are malicious. If the file does not match a signature or hash in the DAT file, and the file meets proprietary criteria, a query is sent to the cloud to check the file against the Trellix GTI technology database. The Trellix GTI File Reputation service provides an instant reputation score that is interpreted by the Threat Prevention to apply a policy, such as block or quarantine. The result is near real-time protection of your endpoint against new and emerging malware.
Note
The system must have Internet connection to access Trellix GTI.
Sensitivity levels of Trellix GTI
You can configure the sensitivity level that Trellix GTI uses when it determines if a detected sample is malware.
verylow — The detections and risk of false positives are the same as with regular DAT content files. A detection is made available to Threat Prevention when Trellix Advanced Research Center publishes it instead of waiting for the next DAT content file update.
low — This setting is the minimum recommendation for systems with a strong security footprint.
medium — Use this level when the regular risk of exposure to malware is greater than the risk of a false positive. Trellix Advanced Research Center proprietary, heuristic checks result in detections that are likely to be malware. However, some detections might result in a false positive. With this setting, Trellix Advanced Research Center checks that popular applications and operating system files don't result in a false positive.
high — Use this setting for deployment to systems or areas which are regularly infected.
veryhigh — Detections found with this level are presumed malicious, but haven't been fully tested to determine if they are false positives. Trellix recommends to use this level for systems that require highest security.
The Trellix GTI sensitivity level is set to medium for both on-access scanning and on-demand scanning by default. The higher the sensitivity level, the higher the number of malware detections. But, allowing more detections can result in more false positive results.
For more information about Trellix GTI, see KB53735.