You can view detailed information about the files and certificates in the TIE server database and make a note of the change in reputation settings for any investigation and remediation.
The longer a client or module runs in your environment, the more populated the database. A file or certificate is added to the database when a client requests information about it.
The default filters show the following options.
For files, you can see files with at least one file name and with a valid composite reputation to prioritize files already seen at the endpoints.
With the Certificate Search you can see only certificates that actually sign files to avoid unnecessary overriding.
You can view information about the file and certificates including:
The associated certificate for a specific file
Details about a certificate's parent certificate
Details about a file's parent process
Current reputations for enterprise, Trellix GTI, Skyhigh Web Gateway, Intelligent Sandbox, Intelligent Virtual Execution, IVX Cloud.
Information of SHA-1, SHA-256, and MD5 hashes
Company information
File name, version, type, and company information
Systems that ran a specific file
Systems that ran files signed by a specific certificate
List of files and certificates signed by a given certificate
Note
The TIE Reputations page is view-only and requires permission to access it. To set permissions to access the fabric, use the Trellix TIE Reputations page permission set in ePO - On-prem.
On the TIE Reputations page on the File Search tab, you see files with metadata that are searchable. The page can show the file type by default. The page shows these columns, for example:
Composite Reputation — Potential effective reputation score based on local reputation (if available) or an estimate based on other reputation scores (if the hash value isn't available at the endpoints).
Important
The Composite Reputation is an estimation until the endpoint reports back what happened in the endpoint. After getting the updated information such as updated reputation from Trellix GTI, the updated information becomes the latest estimation until the next report, and this cycle continues.
The hierarchy used to display the estimation is as follows.
Reputation hierarchy: File Enterprise Reputation, Certificate Enterprise Reputation, Latest Local Reputation.
If there is a reputation (whether it's definitive or not) for any of these sources, the value is shown in the Composite Reputation column with the hierarchy mentioned before.
Reputation hierarchy: Certificate GTI Reputation, File GTI Reputation, IVX Reputation, TIS Reputation, IVX Cloud Reputation, SWG Reputation, and External Reputation.
If there isn't a reputation available for the previous ones (File Enterprise, Certificate Enterprise, and Latest Local), the hierarchy rule changes as described before.
If all or some of those sources have a definitive reputation, the composite estimation shows the reputation from the top provider on the hierarchy.
If none of those sources have a definitive reputation, the composite estimate shows the reputations available based on the hierarchy defined above.
Latest Local Reputation — Last effective reputation score informed by the endpoints of a hash.
Latest Applied Rule — Last content rule applied at the endpoints for determining the effective score of the hash.
On the TIE Reputations page, select Actions → Choose column to customize and add more columns.