If a file's reputation is unknown, you can submit it to Sandbox server for further analysis. Use the TIE server settings to specify which files you submit.
Sandbox server detects zero-day malware and combines anti-virus signatures, reputation, and real-time emulation defenses. You can send files automatically from Adaptive Threat Protection to Sandbox server based on their reputation level and file size. File reputation information sent from Sandbox server is added to the TIE server database.
Trellix GTI telemetry information
The file and certificate information sent to Adaptive Threat Protection is used to understand and enhance reputation information. See the table for details about the information provided by Adaptive Threat Protection for files and certificates, file-only, or certificate-only.
Category | Description |
|---|---|
File and certificate |
|
File-only |
|
Certificate-only |
|
Trellix does not collect personally identifiable information, and does not share information outside of Trellix.