Threat Intelligence Exchange verifies the reputation of executable programs on the endpoints connected to these files.
When you add a ePO - On-prem device to Trellix ESM, the system automatically detects if a TIE server is connected to the device. If it is, Trellix ESM starts listening in on the Trellix Data Exchange Layer and logging events.
Note
A delay might occur when Trellix ESM connects to the DXL.
When the system detects a TIE server, the system adds TIE watchlists, data enrichment, and correlation rules automatically and enables TIE alarms. You receive a visual notification, which includes a link to a summary of changes. The system also notifies you if the TIE server is added to the ePO - On-prem server after the device is added to Trellix ESM.
Once TIE generates events, you can view their execution history and select the actions to take on the malicious data.
Correlation rules
The system optimizes correlation rules for TIE data. They generate events that you can search and sort through.
TIE — Trellix GTI reputation changed from clean to dirty
TIE — Malicious file (SHA-1) found on increasing number of hosts
TIE — Malicious file name found on increasing number of hosts
TIE — Multiple malicious files found on single host
TIE — TIE reputation changed from clean to dirty
TIE — Increase in malicious files found across all hosts
View event rule
View the rule details and the normalization hierarchy of the event selected.
On the Trellix ESM dashboard, select an event form the Events pane.
Click → to view the event information on the ESM Rules page.
Click Normalization Name to view the normalization taxonomy information of the selected event.
Alarms
Trellix ESM has two alarms that might trigger when the system detects important TIE events.
TIE bad file threshold exceeded triggers from the correlation rule TIE - Malicious file (SHA-1) found on increasing number of hosts.
TIE unknown file executed triggers from a specific Threat Intelligence Exchange event and adds information to the TIE data source IPs watchlist.
Watchlist
The TIE data source IPs watchlist maintains a list of systems that have triggered the TIE unknown file executed alarm. It is a static watchlist without expiration.
.png)