The server stores information about file and certificate reputations, then passes that information to other systems in your environment.
The server enables you to:
Control what is allowed to run in your environment. For example, if your organization routinely uses a file that has an unknown security reputation but you know it's safe, you can set its reputation to allow the file to run.
Instantly stop threats from spreading throughout your environment. As soon as the reputation of a file or certificate is detected as malicious (or suspicious, depending on your settings) the file is immediately blocked from running anywhere in your environment.
Identify which files were blocked and where they tried to run. You can see where threats originate and see patterns as they occur. For example, specific systems might be more prone to detecting and blocking malicious files, so you can increase the security settings on those systems.
Identify and track new files that try to run in your environment. If the new file is allowed to run, the server identifies the first system to run the file, and all other systems that ran the file.
Generate dashboards and reports on the managed local threat intelligence.
Bridging DXL fabrics
If you have TIE servers and endpoints managed by different ePO - On-prem systems, you can combine them to share reputation information. For more details, see Trellix Data Exchange Layer Product Guide and KB88621.