The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Threat Intelligence Exchange and its components

Prev Next

Threat Intelligence Exchange is an optional Trellix ENS module that enables you to create policies to block, or clean files based on reputation.

Threat Intelligence Exchange also integrates with:

  • TIE server — A server that stores information about file and certificate reputations, then passes that information to other systems.

  • Trellix DXL — Clients and brokers that enable bidirectional communication between the Threat Intelligence Exchange module on the managed system and the TIE

Note

For installing Threat Intelligence Exchange, you must have installed Trellix ENS Threat Prevention.

These components include ePO - On-prem extensions that add several new features and reports.

Scenarios for using Threat Intelligence Exchange

  • Immediately block a fileThreat Intelligence Exchange alerts the network administrator of an unknown file in the environment. Instead of sending the file information to Trellix for analysis, the administrator blocks the file immediately. The administrator can then use TIE server, if available, to learn how many systems ran the file.

  • Allow a custom file to run — A company routinely uses a file whose default reputation is suspicious or malicious, for example a custom file created for the company. Because this file is allowed, instead of sending the file information to Trellix and receiving an updated content daily, the administrator can change the file's reputation to trusted and allow it to run.