The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Retrieving files and certificates

Prev Next

You can view detailed information about the files and certificates in the TIE server database and make a note of the change in reputation settings for any investigation and remediation.

The longer a client or module runs in your environment, the more populated the database. A file or certificate is added to the database when a client requests information about it.

The default filters show the following options.

  • For files, you can see files with at least one file name and with a valid composite reputation to prioritize files already seen at the endpoints.

  • With the Certificate Search you can see only certificates that actually sign files to avoid unnecessary overriding.

You can view a host of information about the file and certificates, which includes:

  • The associated certificate for a specific file

  • Details about a certificate's parent certificate

  • Details about a file's parent process

  • Current enterprise, Trellix GTI, Skyhigh Web Gateway, Intelligent Sandbox, Intelligent Virtual Execution

  • Information of SHA-1, SHA-256, and MD5 hashes

  • Company information

  • File name, version, type, and company information

  • Systems that ran a specific file

  • Systems that ran files signed by a specific certificate

  • List of files and certificates signed by a given certificate

Note

The TIE Reputations page is view-only and requires permission to access it. To set permissions to access the fabric, use the Trellix TIE Reputations page permission set in Trellix ePO - On-prem.

On the TIE Reputations page on the File Search tab, you see files with metadata and that are searchable. The page can show the file type by default. The page shows these columns, for example:

  • Composite Reputation — Potential effective reputation score based on local reputation (if available) or an estimate based on other reputation scores (if the hash value isn't available at the endpoints).

    Important

    The Composite Reputation is an estimation until the endpoint reports back what did really happen in the endpoint. After getting the updated information such as updated reputation from Trellix GTI, the updated information becomes the latest estimation until the next report, and this cycle continues.

    The hierarchy used to display the estimation is as follows.

    • Reputation hierarchy: File Enterprise Reputation, Certificate Enterprise Reputation, Latest Local Reputation.

      If there is a reputation (whether it's definitive or nor) for any of these sources, the value is show in the Composite Reputation column with the hierarchy mentioned before.

    • Reputation hierarchy: Certificate GTI Reputation, File GTI Reputation, IVX Reputation, TIS Reputation, SWG reputation, and External reputation.

      If there isn't a reputation available for the previous ones (File Enterprise, Certificate Enterprise, and Latest Local), the hierarchy rule changes as described before.

      If all or some of those sources have a definitive reputation, the composite estimation shows the reputation from the top provider on the hierarchy.

      If none of those sources have a definitive reputation, the composite estimate shows the reputations available based on the hierarchy defined above.

  • Latest Local Reputation — Last effective reputation score informed by the endpoints of a hash.

  • Latest Applied Rule — Last content rule applied at the endpoints for determining the effective score of the hash.

On the TIE Reputations page, select ActionsChoose column to customize and add more columns.