In STIX import wizard, there are 10 columns that show the details of the file imported. See the table Option definitions to learn about each of them.
Option | Definition |
|---|---|
SHA1 | It is a hash value that identifies a file. |
MD5 | It is a hash value necessary to perform a file import because TIE interacts with Trellix Global Threat Intelligence. For more information about Trellix Global Threat Intelligence interaction with TIE, see Trellix Trellix Global Threat Intelligence web page. |
SHA256 | It is a hash value that identifies a file. |
ImportantWhen there are no hash values present, the hash column is not displayed. | |
Filename in STIX | It is the name of the file to be imported. The name might be present or not. |
Enterprise reputation | It shows the enterprise reputation as it appears in TIE. This reputation that might be present or not. If it is not present, it means that it is not present in TIE environment. |
GTI reputation | Trellix Global Threat Intelligence is the main reputation source that TIE uses. |
ATD reputation | Intelligent Sandbox (ATD) reputation might be present or not. If no results are shown, it means one of the following options:
|
Local reputation | It shows the reputation given by the TIE client. |
Enterprise count | It shows how many times the TIE environment has viewed the file. If there isn't an enterprise count, the reputation value has not been set. |
VirusTotal detection ratio | It shows how many times different tools detected a file and the reputation given by those tools. For more information about VirusTotal detections, go to www.virustotal.com. |
Validations | See Validations in STIX import. |