Assess, prioritize, analyze, and react against threats using the TIE services activities in Trellix ePO - On-prem.
We provide a brief introduction and overview of each activity. See KB86307 for details about each activity.
For an effective use of TIE services capabilities, follow a repeatable and scalable workflow to prioritize and analyze high impact or prevalent threats in the managed environment.
Assessing — The dashboards for TIE Server Files or TIE Server Certificates quickly assess the health status of the environment.
From the Custom menu you add a new dashboard and specify a name and its visibility.
Navigate: To create a custom dashboard, Dashboards → Dashboards Actions → Custom → Add.
Prioritizing — The default filters and the Query and Reports system in Trellix ePO - On-prem determine which files or certificates are a priority for analysis.
Navigate: TIE Reputations → File Search → Custom, or TIE Reputations → Certificate Search → Custom.
Analyzing — It presents the list of associated files or certificates, their parent files or certificates, where they were run, and their details including behavioral attributes.
Navigate: TIE Reputations → TIE Files Reputations, then select an option. Navigate to TIE Certificate Reputations, then select an option.
Reacting — The manual overrides handle existing malware and protect the environment against future executions. The Trellix ePO - On-prem can list queries for the systems that were tagged as compromised.
Navigate: TIE Reputations → File Search → Actions → System Health Indicator → Set Possibly Compromised