Application Control works with multiple sources to fetch reputation information for files and certificates.
Important
Reputation information is available only in a ePO - On-prem managed environment.
Application Control supports reputation-based execution. When you run a file at an endpoint, the software fetches its reputation and reputation of all certificates associated with the file to determine whether to allow or ban the file execution. The settings configured for your enterprise determine the reputation values that are allowed and banned.
Reputation sources
Based on the configuration, the software regularly synchronizes with these sources:
TIE server – The TIE server is a local reputation server that communicates with multiple reputation sources. It effectively combines and collates intelligence from global sources with local threat intelligence and customized organizational knowledge to provide aggregated reputation values.
Trellix GTI server – Trellix GTI is a cloud-based service that functions as a reputation source. Application Control periodically synchronizes with the Trellix GTI server to fetch ratings for executable files and certificates. The Fetch File Details from Trellix GTI Server and Fetch Certificate Reputation from Trellix GTI Server tasks are internal tasks that run automatically several times a day to fetch Trellix GTI ratings for executable files and certificates.
Communication with TIE server and Trellix GTI
Here is how Application Control communicates with the TIE server and Trellix GTI server.
TIE server – Application Control communicates directly with the TIE server configured in your environment.
Trellix GTI– Application Control communicates directly with the Trellix GTI server. But, if a proxy server is configured in your setup, Application Control uses it to communicate with the Trellix GTI server. The proxy server is configured on the Menu → Configuration → Server Settings → Proxy Settings page.
With 8.3.0, 8.2.1, and earlier versions we fetched Trellix GTI using SHA1 and cert hashes from both URLs below.
TACC extension 8.2.6 started supporting TLS Protocol version 1.2 for Trellix GTI. This is done by updating Trellix GTI server URL along with all the underlying Trellix GTI APIs.
TIE Enterprise reputation source
You can configure Application Control to use TIE as the exclusive source for file reputations. When you enable the TIE Enterprise Trust Level option in the Application Control Options (Windows) policy, the software disables Trellix GTI and Trellix Intelligent Sandbox reputations.
Note the following behaviors:
You must configure this option in the ePO - On-prem policy. You cannot modify this setting on the endpoint.
When this policy is enabled, users cannot enable the Trellix GTI reputation feature on endpoints.
If a user disables the TIE reputation feature on the endpoint, the software disables the TIE Enterprise Trust Level locally and resets the value to zero.
Use the
TieEnterpriseLevelTrustEnableproperty in the System Tree to verify the status of this setting for each endpoint.
Reputation display for TIE overrides
The Solidcore Events page adds an (Enterprise) suffix to reputations overridden by a user in the TIE Reputations page. This suffix appears for events where the deny reason is TIE - Malicious process SHA-1 or TIE - Malicious Certificate.
The Reputation column displays these reputations as:
Known Malicious (Enterprise)
Most Likely Malicious (Enterprise)
Might Be Malicious (Enterprise)
Firewall URL and ports needed for GTI communication:
8.3.0, 8.2.1 and below:
URL | Ports |
|---|---|
Cwl2.gti.mcafee.com | 443 |
Mace.rest.gti.mcafee.com | 443 |
8.2.6, 8.3.1, 8.3.2, 8.3.3, 8.3.4, and 8.3.5:
URL | Ports |
|---|---|
Mace.rest.gti.mcafee.com | 443 |
8.3.6 or later:
URL | Ports |
|---|---|
solidcore.rest.gti.trellix.com | 443 |