Application Control communicates with TIE and Trellix GTI servers at regular intervals to fetch reputation information for executable files and certificates.
Values from TIE server
The TIE server offers scores from various providers, such as Trellix Intelligent Sandbox, Trellix GTI, and event trace logs (ETL) that Application Control uses to compute reputation.
Known trusted – A trusted file or certificate.
Most likely trusted – Almost certainly a trusted file or certificate.
Might be trusted – Seemingly a benign file or certificate.
Unknown – The reputation provider can't determine its reputation at the moment.
Might be malicious – A suspicious file or certificate.
Most likely malicious – Almost certainly a malicious file or certificate.
Known malicious – A malicious file or certificate.
Not set – Undetermined file or certificate reputation.
Values from Trellix GTI
For each executable file, Trellix GTI provides the reputation and classification values.
File Hash Reputation indicates if the file is trusted or malicious. Based on information fetched from Trellix GTI, the application and files are sorted into categories on the Application Control pages.
File Hash Classification indicates the reliability or credibility of the file. The assigned value indicates if the file is trusted, unknown, or malicious.
For each certificate, Trellix GTI provides a score that indicates its reputation.
Trellix GTI classification for files | Trellix GTI score for certificates | Description |
|---|---|---|
known_clean | 99 | Known trusted |
analysed_clean, assumed_clean | 85 | Most likely trusted |
raiden_analyzed_clean, noise_clean | 70 | Might be trusted |
unknown | 50 | Unknown |
assumed_dirty, assumed_dirty2 | 30 | Might be malicious |
assumed_dirty3, assumed_dirty4 | 15 | Most likely malicious |
pup, trojan, virus, app | 1 | Known malicious |
Not available | 0 | Not set |
Values from Application Control
Application Control can track the enterprise trust level or reputation by Application Control value for each executable file. When edited, this value for a file overrides the existing reputation for the file.
For example, your organization uses an internally developed application that is set as an unknown application because it is specific to your organization. Because you trust the application, you can recategorize it as a trusted file by editing its reputation. The values are:
Known Malicious
Unknown
Known Trusted