The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Submitting files for further analysis

Prev Next

If a file's reputation is unknown, you can submit it to Sandbox server for further analysis. Use the TIE server settings to specify which files you submit.

Sandbox server detects zero-day malware and combines anti-virus signatures, reputation, and real-time emulation defenses. You can send files automatically from Adaptive Threat Protection to Sandbox server based on their reputation level and file size. File reputation information sent from Sandbox server is added to the TIE server database.

Trellix GTI telemetry information

The file and certificate information sent to Adaptive Threat Protection is used to understand and enhance reputation information. See the table for details about the information provided by Adaptive Threat Protection for files and certificates, file-only, or certificate-only.

Category

Description

File and certificate

  • TIE server and module versions

  • Reputation override settings made with the TIE server

  • External reputation information, for example from Sandbox server

File-only

  • File name, type, path, size, product, publisher, and prevalence

  • SHA-1, SHA-256, and MD5 information

  • Operating system version of the reporting computer

  • Maximum, minimum, and average reputation set for the file

  • Whether the reporting module is in Observe mode

  • Whether the file was allowed to run, was blocked, contained, or cleaned

  • The product that detected the file, for example Sandbox server or Threat Prevention

Certificate-only

  • SHA-1 information

  • The name of the certificate's issuer and its subject

  • The date the certificate was valid and its expiration date

Trellix does not collect personally identifiable information, and does not share information outside of Trellix.