Review details of STIX import

Prev Next

In STIX import wizard, there are 10 columns that show the details of the file imported. See the table Option definitions to learn about each of them.

Option definitions

Option

Definition

SHA1

It is a hash value that identifies a file.

MD5

It is a hash value necessary to perform a file import because TIE interacts with Trellix Global Threat Intelligence. For more information about Trellix Global Threat Intelligence interaction with TIE, see Trellix Trellix Global Threat Intelligence web page.

SHA256

It is a hash value that identifies a file.

Important

When there are no hash values present, the hash column is not displayed.

Filename in STIX

It is the name of the file to be imported. The name might be present or not.

Enterprise reputation

It shows the enterprise reputation as it appears in TIE. This reputation that might be present or not. If it is not present, it means that it is not present in TIE environment.

GTI reputation

Trellix Global Threat Intelligence is the main reputation source that TIE uses.

ATD reputation

Intelligent Sandbox (ATD) reputation might be present or not. If no results are shown, it means one of the following options:

  • Intelligent Sandbox is not installed in your environment.

  • Intelligent Sandbox has no records of the file.

  • TIE and Intelligent Sandbox haven't viewed the file, or

  • The environment has not viewed the file.

Local reputation

It shows the reputation given by the TIE client.

Enterprise count

It shows how many times the TIE environment has viewed the file. If there isn't an enterprise count, the reputation value has not been set.

VirusTotal detection ratio

It shows how many times different tools detected a file and the reputation given by those tools. For more information about VirusTotal detections, go to www.virustotal.com.

Validations

See Validations in STIX import.