Trellix Threat Intelligence Exchange - SaaS Installation Guide

Prev Next

Accessing Trellix Threat Intelligence Exchange - SaaS

To start using Trellix Threat Intelligence Exchange - SaaS, you must first sign up for an Trellix ePolicy Orchestrator - SaaS account and activate it.

After you log on to Trellix ePO - SaaS, you can access the TIE Reputations page if you have a valid TIE license.

You need to deploy Trellix Endpoint Security (ENS) Adaptive Threat Protection on endpoints to manage TIE reputations on Trellix ePO - SaaS platform.

Note

For information about the features of Trellix Threat Intelligence Exchange - SaaS, see Trellix Threat Intelligence Exchange - SaaS Product Guide.


System requirements

For details about system requirements of client Endpoint Security Adaptive Threat Protection, see Trellix Endpoint Security (ENS) Installation Guide and KB82761.

You can download the latest versions of Trellix Agent and Trellix Data Exchange Layer from Trellix ePO - SaaS.

Assign roles to users

You can limit or extend users' access to Trellix TIE - SaaS by assigning or unassigning roles. All roles have specific permission sets assigned to them.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.

  2. Select Menu → Configuration → Users & Roles.

  3. On the Users & Roles page, select a user from the Users pane.

    The user details, assigned roles, and unassigned roles for the selected user appears on the right pane.

  4. Select the required roles from the Unassigned Roles list. The Roles pane lists the created roles.

  5. Click Save Changes.

Invite users to manage Trellix TIE - SaaS

You can add users and assign specific roles to them to use Trellix TIE - SaaS.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.

  2. Select Menu → Configuration → Users & Roles.

  3. On the Users & Roles page, click Invite User.

  4. On the Invite new user page, type the first name, last name, and the email address of the user you want to invite.

  5. Click Invite.

Results

An invitation email is sent to the user with activation instructions. This invitation is valid for 7 days. After you add the user, their names appear on the Users pane.

Create a role

You can use the default permissions for Trellix threat intelligence service and Trellix ePO - SaaS to create a customized role for your user.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.

  2. Select Menu → Configuration → Users & Roles.

  3. On the Users & Roles page, click Add Role.

  4. Enter a name for the role.

    Roles Trellix Threat Intelligence Administrator and Trellix Threat Intelligence Viewer are available to duplicate to users.

  5. From the below products, select the required permissions:

    1. From the Trellix Threat Intelligence Service drop-down list, user administrator can select Manage Reputations with administrator permissions to manage reputations and View Reputations with view only permissions to view reputations.

    2. From the Trellix ePolicy Orchestrator - SaaS drop-down list, select the required permissions.

    The selected permissions appear in Assigned Permissions.

Results

The created role appears in the Roles pane. You can now assign this role to selected users.

Delete users and roles

You can remove all roles and users when they are no longer in use. The default roles can't be deleted.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.

  2. Select Menu → Configuration → Users & Roles.

  3. On the Users & Roles page, select the user or role that you want to delete.

  4. Click Delete, then click Confirm.

Results

The user role is removed from the Users or Roles list.

Duplicate a role

You can create a copy of an existing role and customize as needed.

Before you begin

Make sure that you have administrator permissions to use Trellix ePO - SaaS.

Task

  1. Log on to Trellix ePO - SaaS as an administrator.

  2. Select Menu → Configuration → Users & Roles.

  3. On the Users & Roles page, select the role that you want to copy:

    1. Trellix Threat Intelligence Administrator — with administrator permissions to manage reputations.

    2. Trellix Threat Intelligence Viewer — with view only permissions to view reputations.

  4. Click Duplicate.

Results

A copy of the existing role is created. You can edit the role name, assign or unassign permissions, and save the role.

Trellix Threat Intelligence Exchange - SaaS Installation Guide  7

4 | Getting started with Trellix Threat Intelligence Exchange - SaaS


Deploy client ATP using Trellix ePO - SaaS

For details about deploying client Adaptive Threat Protection using Trellix ePO - SaaS, see Trellix Endpoint Security (ENS) Installation Guide.

Deploy DXL local broker using Trellix ePO - SaaS

DXL local broker keeps file and reputation cache and reduces endpoints effort to reach the TIE services for reputation.

Blue note icon Note

DXL local broker is an optional component.

DXL local broker is mandatory for TIE services integration with on-premises infrastructure Intelligent Sandbox for sandboxing analysis of file samples.

For details about deployment and configure DXL local broker, and connect DXL client with DXL local broker, see Trellix Data Exchange Layer Installation Guide.