The client Trellix Endpoint Security (ENS) Adaptive Threat Protection 10.7.x or later allows you to determine what happens when a file with a malicious or unknown reputation is detected in your environment. You can also view threat history information and the actions taken.
The client uses rules for determining actions based on multiple data points such as reputations, local intelligence, and contextual information. You can enable some optional rules. For more information about Trellix ENS product documentation, see www.docs.trellix.com.
The client applies policies and scans files to determine whether to send the files to the sandbox.