Scenarios where you might override reputations

Prev Next

You can allow or block a file or certificate in your environment if there is false positive mitigation or for managing unknown reputations.

In certain scenarios, you might adjust the reputation for a file or certificate in your environment as an override, for example, to mitigate false positives when Trellix ENS has incorrectly blocked a file that you know might be trusted. For other scenarios, see 000013593 for details about reputation management.

Automation should rely on external reputations and not on the overrides since the override of reputations aren't safe in case of false positives.

  1. In ePO - SaaS, select MenuSystemsTIE Reputations.

  2. Click the File Search or Certificate Search tab.

  3. Search for files or certificates by name or by file type, such as .dll or .exe. You can also use wildcard search characters * or ?.

    To view details about a specific file or certificate, including its hash number, click its name. Examine the details and VirusTotal information for the file to determine how to classify it.

    To view details about a specific file or certificate, including its hash number, click its name. Examine the details for the file to determine how to classify it.

  4. Select items in the list and use the Actions menu to change the reputation settings. The files or certificates are then added to the overrides list.

    You can add a note about the change, for example, Researched the file's reputation. Blocking this file. #369845: false positive (jsmith, 0604221584)

  5. To make sure the change is implemented, click the File Overrides or Certificate Overrides tab to see that the file or certificate is listed with its updated reputation.