You can view detailed information about the files and certificates in the TIE services database and make a note of the change in reputation settings for any investigation and remediation.
The longer a client runs in your environment, the more populated the database. A file or certificate is added to the database when a client requests information about it.
The default filters show the following options.
For files, you can see files with at least one file name and with a valid composite reputation to prioritize files already seen at the endpoints.
With the Certificate Search, you can see only certificates that actually sign files to avoid unnecessary overriding.
You can view a host of information about the file and certificate, which include:
The associated certificate for a specific file
Details about a certificate's parent certificate
Details about a file's parent process
Current enterprise, Trellix GTI, Intelligent Sandbox, IVX, and IVX Cloud reputation
Information of SHA-1, SHA-256, and MD5 hashes
Company information
File name, version, type, and company information
Systems that ran a specific file
Systems that ran files signed by a specific certificate
List of files and certificates signed by a given certificate
Note
The TIE Reputations page requires permission to access it. The ePO - SaaS user administrator can give permissions to manage and view reputations to their users.
On the TIE Reputations page, select File Search tab, you see files with metadata and that are searchable. The page can show the file type by default. The page shows these columns, for example:
Composite Reputation — Potential effective reputation score based on local reputation (if available) or an estimate based on other reputation scores (if the hash value isn't available at the endpoints).
Important
The Composite Reputation is an estimation until the endpoint reports back what did really happen in the endpoint. After getting the updated information such as updated reputation from Trellix GTI, the updated information becomes the latest estimation until the next report, and this cycle continues.
The hierarchy used to display the estimation is as follows.
Reputation hierarchy: Enterprise Reputation, Certificate Enterprise Reputation, Latest Local Reputation.
If there is a reputation (whether it's definitive or not) for any of these sources, the value is shown in the composite reputation column with the hierarchy mentioned before.
Reputation hierarchy: Certificate GTI Reputation, GTI Reputation, TIS Reputation, IVX Reputation, IVX Cloud Reputation, and External reputation.
If there isn't a reputation available for the previous ones (enterprise reputation, certificate enterprise reputation, and latest local reputation), the hierarchy rule changes as described before.
If all or some of those sources have a definitive reputation, the composite estimation shows the reputation from the top provider on the hierarchy.
If none of those sources have a definitive reputation, the composite estimate shows the reputations available based on the hierarchy defined above.
Latest Local Reputation — Last effective reputation score informed by the endpoints of a hash.
Latest Applied Rule — Last content rule applied at the endpoints for determining the effective score of the hash.
On the TIE Reputations page, select → to customize and add more columns.