The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Submitting files for further analysis

Prev Next

If a file's reputation is unknown, you can submit it to Intelligent Sandbox for further analysis. Use the TIE server settings to specify which files you submit.

If a file's reputation is unknown, you can submit it to Intelligent Sandbox for further analysis. Use the TIE server settings to specify which files you submit.You can send files automatically from TIE server to Intelligent Sandbox based on their reputation level and file size.If a file's reputation is unknown, you can submit it to Intelligent Sandbox for further analysis. Use the TIE server settings to specify which files you submit.

Trellix GTI telemetry information

The file and certificate information sent to Trellix GTI is used to understand and enhance reputation information. See the table for details about the information provided by Trellix GTI for files and certificates, file-only, or certificate-only.

Important

Consider that this is detection telemetry, not product telemetry.

Category

Description

File and certificate

  • TIE server and client versions

  • Reputation override settings made with the TIE server

  • External reputation information, for example from Intelligent Sandbox

File-only

  • File name, type, path, size, product, publisher, and prevalence

  • SHA-1, SHA-256, and MD5 information

  • Operating system version of the reporting computer

  • Maximum, minimum, and average reputation set for the file

  • Whether the reporting client is in Observation mode

  • Whether the file was allowed to run, was blocked, or was cleaned

  • The product that detected the file, for example Intelligent Sandbox or Threat Prevention

Note

The username is obfuscated at the endpoint if the path contains it.

Certificate-only

  • SHA-1 information

  • The name of the certificate's issuer and its subject

  • The date the certificate was valid and its expiration date

Trellix does not collect personally identifiable information, and does not share information outside of Trellix.