You can use the Offline Trellix GTI tool to fetch ratings for files and certificates with no access to the Internet.
Make sure that Java Runtime Environment (JRE) 1.6.0_33 or later is installed on the system.
Verify that the system is connected to the internet.
Make sure that you have downloaded and saved the
OfflineGTITool.zipfile from the Trellix download site.
For all file SHA-1s, File Hash Reputation and File Hash Classification values are fetched from the Trellix GTI file reputation service. Similarly, for public key SHA-1s of certificates, corresponding reputation values are fetched from the Trellix GTI server. The Offline Trellix GTI tool fetches the Trellix GTI ratings and saves the information to a result file.
Note
Trellix GTI file reputation service and the server don't support SHA-256 files and public key SHA-256 certificates.
Set the GTI_TOOL_JAVA_HOME environment variable.
Open a command window.
Type this command and provide the path to the JRE.
set GTI_TOOL_JAVA_HOME=<JRE path>For example:
set GTI_TOOL_JAVA_HOME=C:\Program Files\Java\jre6
Run the Offline Trellix GTI tool.
Extract the
OfflineGTITool.zipfile to a system with access to the Internet.The
OfflineGTITooldirectory is created. This directory contains thereadme.txtfile that explains the prerequisites, procedure, configuration, and logging details. For detailed information about using the Offline Trellix GTI tool, we recommend that you read this file.Change to the
OfflineGTITooldirectory.cd <directory path>Make sure that you specify the absolute path to the
OfflineGTITooldirectory.Verify that the current directory is
OfflineGTITool.cdRun the tool.
runOfflineGTITool.cmd <Inventory file path>Specify the tool name followed by the path to the inventory file that you saved on this system.
For example:
runOfflineGTITool.cmd c:\inventory\App-Control-Inventory-yyyy-MM-dd_HH-mm-SS.zip
The Offline Trellix GTI tool connects to the Trellix GTI server and fetches Trellix GTI ratings for the file SHA-1s and certificate public key SHA-1s. When ratings for all SHA-1s and public key SHA-1s are fetched, a success or failure message is displayed at the command prompt. The created Trellix GTI result file contains the Trellix GTI ratings and its contents are encrypted. The file name is appended with the date and time when the file is created.
GTI-Result-<year>-<month>-<day>_<hour>-<minute>-<second>.zipCopy the Trellix GTI result file to a system connected to the ePO - On-prem server.