The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Submitting file samples to IVX Cloud

Prev Next

If a file's reputation is unknown in the TIE services and Trellix GTI, TIE, working with endpoint components, can facilitate the submission of the file to IVX Cloud for sandboxing. IVX Cloud detects zero-day malware and combines antivirus signatures, reputation, and real-time emulation defenses. You can send files automatically from the TIE services to IVX Cloud through IVX Cloud API based on their reputation level and file size. File reputation information sent from IVX Cloud is added to TIE services database.

Note

You need to have a IVX Cloud subscription to send the files to IVX Cloud for sandboxing.

IVX Cloud workflow

  1. An endpoint requests a file reputation to the TIE services.

  2. The endpoint receives all available reputations. If the reputation is unknown, TIE can recommend the file as a candidate for sandboxing on IVX Cloud.

  3. The endpoint analyzes the content rules based on the response and determines sample file should be submitted for sandboxing.

    Note

    By default, the file's local reputation must be unknown and the file size less than 5 MB.

  4. The endpoint submits the binary file directly to TIE Server.

  5. TIE Server sends the binary file request to IVX Cloud for sandboxing.

  6. The TIE Server intermittently polls IVX Cloud for the results of the sandboxing.

  7. When the result is available, TIE Server stores the result and broadcasts the reputation over DXL to endpoints.