Reputation values received from sources

Prev Next

Application Control communicates with TIE and Trellix GTI servers at regular intervals to fetch reputation information for executable files and certificates.

Values from TIE server

The TIE server offers scores from various providers, such as Trellix Intelligent Sandbox, Trellix GTI, and event trace logs (ETL) that Application Control uses to compute reputation.

  • Known trusted – A trusted file or certificate.

  • Most likely trusted – Almost certainly a trusted file or certificate.

  • Might be trusted – Seemingly a benign file or certificate.

  • Unknown – The reputation provider can't determine its reputation at the moment.

  • Might be malicious – A suspicious file or certificate.

  • Most likely malicious – Almost certainly a malicious file or certificate.

  • Known malicious – A malicious file or certificate.

  • Not set – Undetermined file or certificate reputation.

Values from Trellix GTI

For each executable file, Trellix GTI provides the reputation and classification values.

  • File Hash Reputation indicates if the file is trusted or malicious. Based on information fetched from Trellix GTI, the application and files are sorted into categories on the Application Control pages.

  • File Hash Classification indicates the reliability or credibility of the file. The assigned value indicates if the file is trusted, unknown, or malicious.

For each certificate, Trellix GTI provides a score that indicates its reputation.

Trellix GTI classification for files

Trellix GTI score for certificates

Description

known_clean

99

Known trusted

analysed_clean, assumed_clean

85

Most likely trusted

raiden_analyzed_clean, noise_clean

70

Might be trusted

unknown

50

Unknown

assumed_dirty, assumed_dirty2

30

Might be malicious

assumed_dirty3, assumed_dirty4

15

Most likely malicious

pup, trojan, virus, app

1

Known malicious

Not available

0

Not set

Values from Application Control

Application Control can track the enterprise trust level or reputation by Application Control value for each executable file. When edited, this value for a file overrides the existing reputation for the file.

For example, your organization uses an internally developed application that is set as an unknown application because it is specific to your organization. Because you trust the application, you can recategorize it as a trusted file by editing its reputation. The values are:

  • Known Malicious

  • Unknown

  • Known Trusted