The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Submitting file samples to Trellix Intelligent Sandbox (TIS)

Prev Next

All TIE server instances (except Write-Only Primary and Reporting Secondary) can forward file samples to Trellix Intelligent Sandbox for analysis.

On the Sandboxing tab in the Intelligent Sandbox section, you can configure which file types are enabled for submitting them to analysis.

From the Available File Types list, you select the file types to be sent to Intelligent Sandbox, including Portable Executable (PE) and extended file type support. PE files are enabled by default. For more information, visit https://docs.trellix.com/.

Make sure that the TIE servers and the Intelligent Sandbox instances are connected to secured internal networks. The file sample submission from the TIE server to Intelligent Sandbox uses a TLS connection. To enforce the authentication of the connection, first upload certificates signed by public certificate authorities (CA) to Intelligent Sandbox, then enable the Enforce Certificate Validation policy in the TIE server.

You can locally install trusted CAs certificates or use the certificates provided by Intelligent Sandbox by default.

See KB87692 before enabling the Enforce Certificate Validation policy.

For a list of trusted CA, see OpenJDK 1.8 documentation. For instructions on how to upload the certificates toIntelligent Sandbox, see Trellix Intelligent Sandbox Product Guide.

It is configured via ePO - On-prem policies for different endpoint groups. The Intelligent Sandbox instances can be grouped based on their geographical distribution. You might assign TIE server policies for each group of Intelligent Sandbox instances based on their geographical location. Use this configuration especially in large-scale deployments.

Under Polling Settings, you can choose which Intelligent Sandbox servers should be polled for detonation results. By default all servers are polled. You can change this policy to poll only local Intelligent Sandbox servers for results, or none, which requires DXL integration enabled in Intelligent Sandbox to guarantee that Intelligent Sandbox reports are received by TIE server.

This configuration is used together with DXL broker service zone to determine which broker a reputation request is sent to. See Trellix Data Exchange Layer Product Guide for more details.

See KB86707 for details about this configuration.