The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Recommended workflow

Prev Next

Assess, prioritize, analyze, and react against threats using the TIE services activities in ePO - On-prem.

We provide a brief introduction and overview of each activity. See KB86307 for details about each activity.

For an effective use of TIE services capabilities, follow a repeatable and scalable workflow to prioritize and analyze high impact or prevalent threats in the managed environment.

  1. Assessing — The dashboards for TIE Server Files or TIE Server Certificates quickly assess the health status of the environment.

    From the Custom menu you add a new dashboard and specify a name and its visibility.

    Navigate: To create a custom dashboard, DashboardsDashboards ActionsCustomAdd.

  2. Prioritizing — The default filters and the Query and Reports system in ePO - On-prem determine which files or certificates are a priority for analysis.

    Navigate: TIE ReputationsFile SearchCustom, or TIE ReputationsCertificate SearchCustom.

  3. Analyzing — It presents the list of associated files or certificates, their parent files or certificates, where they were run, and their details including behavioral attributes.

    Navigate: TIE ReputationsTIE Files Reputations, then select an option. Navigate to TIE Certificate Reputations, then select an option.

  4. Reacting — The manual overrides handle existing malware and protect the environment against future executions. The ePO - On-prem can list queries for the systems that were tagged as compromised.

    Navigate: TIE ReputationsFile SearchActionsSystem Health IndicatorSet Possibly Compromised