Reputation sources and communication

Prev Next

Application Control works with multiple sources to fetch reputation information for files and certificates.

Important

Reputation information is available only in a ePO - SaaS managed environment.

Application Control supports reputation-based execution. When you run a file at an endpoint, the software fetches its reputation and reputation of all certificates associated with the file to determine whether to allow or ban the file execution. The settings configured for your enterprise determine the reputation values that are allowed and banned.

Reputation sources

Based on the configuration, the software regularly synchronizes with these sources:

  • Trellix GTI server Trellix GTI is a cloud-based service that functions as a reputation source. Application Control periodically synchronizes with the Trellix GTI server to fetch ratings for executable files and certificates. The Fetch File Details from Trellix GTI Server and Fetch Certificate Reputation from Trellix GTI Server tasks are internal tasks that run automatically several times a day to fetch Trellix GTI ratings for executable files and certificates.

Communication with Trellix GTI

  • Trellix GTIApplication Control communicates directly with the Trellix GTI server. But, if a proxy server is configured in your setup, Application Control uses it to communicate with the Trellix GTI server. The proxy server is configured on the MenuConfigurationServer SettingsProxy Settings page.

  • TACC 9.x.x supports TLS Protocol version 1.2 for Trellix GTI. This is done by updating Trellix GTI server URL along with all the underlying Trellix GTI APIs.

Firewall URL and ports needed for GTI communication:

9.x.x or later:

URL

Ports

solidcore.rest.gti.trellix.com

443