The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Review details of STIX or CSV import

Prev Next

In import wizard, there are 10 columns that show the details of the file imported. See the table Option definitions to learn about each of them.

Option definitions

Option

Definition

STIX: SHA1

CSV: SHA1-1

It is a hash value that identifies a file.

MD5

It is a hash value necessary to perform a file import because TIE interacts with Trellix Global Threat Intelligence. For more information about Trellix Global Threat Intelligence interaction with TIE, see Trellix Trellix Global Threat Intelligence web page.

STIX: SHA256

STIX: SHA-256

It is a hash value that identifies a file.

Important

When there are no hash values present, the hash column is not displayed.

Filename

It is the name of the file to be imported. The name might be present or not.

Enterprise reputation

It shows the enterprise reputation as it appears in TIE. This reputation that might be present or not. If it is not present, it means that it is not present in TIE environment.

GTI reputation

Trellix Global Threat Intelligence is the main reputation source that TIE uses.

TIS reputation

Intelligent Sandbox (TIS) reputation might be present or not. If no results are shown, it means one of the following options:

  • Intelligent Sandbox is not installed in your environment.

  • Intelligent Sandbox has no records of the file.

  • TIE and Intelligent Sandbox haven't viewed the file.

  • The environment has not viewed the file.

IVX reputation

Intelligent Virtual Execution (IVX) reputation might be present or not. If no results are shown, it means one of the following options:

  • IVX is not installed in your environment.

  • IVX has no records of the file.

  • TIE and IVX haven't viewed the file.

  • The environment has not viewed the file.

IVX Cloud reputation

Intelligent Virtual Execution (IVX) Cloud reputation might be present or not. If no results are shown, it means one of the following options:

  • IVX Cloud is not configured in your environment.

  • IVX Cloud has no records of the file.

  • The environment has not viewed the file.

Local reputation

It shows the reputation given by the TIE module. See also TIE Module.

Enterprise count

It shows how many times the TIE environment has viewed the file. If there isn't an enterprise count, the reputation value has not been set.

VirusTotal detection ratio

It shows how many times different tools detected a file and the reputation given by those tools. For more information about VirusTotal detections, go to www.virustotal.com.

Validations

See Validations in STIX or CSV import.