Consider these basic use case scenarios for using the TIE server to block and allow files to run in your environment and to import reputations.
Immediately block a file — Threat Intelligence Exchange server alerts the network administrator of an unknown file in the environment. Instead of sending the file information to Trellix for analysis, the administrator blocks the file immediately. The administrator can then use Threat Intelligence Exchange to learn whether the file is a threat and how many systems ran the file.
Allow a custom file to run — A company routinely uses a file whose default reputation is suspicious or malicious, for example a custom file created for the company. Because this file is allowed, instead of sending the file information to Trellix and receiving an updated DAT file, the administrator can change the file's reputation to trusted and allow it to run without warnings or prompting.
Import known reputations — A company has several files that are trusted and used regularly, and other files that are not allowed. Because the reputations are already known and set, the administrator can import a list of files and their reputations directly into the Threat Intelligence Exchange server database. Those reputations are used immediately with no further action.
See additional information about a file — For any file or certificate with unknown reputation, the Threat Intelligence Exchange server allows the network administrator to inspect its details. The administrator can see several details about the file, such as the file's parent process, company and version information, hash information, and the systems that ran the file. The administrator can also see more detailed information about the file with VirusTotal, a free online scanning service for viruses, malware, and URLs.