The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

TrellixThreat Intelligence Exchange integration

Prev Next

Threat Intelligence Exchange verifies the reputation of executable programs on the endpoints connected to these files.

When you add a ePO - On-prem device to Trellix ESM, the system automatically detects if a TIE server is connected to the device. If it is, Trellix ESM starts listening in on the Trellix Data Exchange Layer and logging events.

Note

A delay might occur when Trellix ESM connects to the DXL.

When the system detects a TIE server, the system adds TIE watchlists, data enrichment, and correlation rules automatically and enables TIE alarms. You receive a visual notification, which includes a link to a summary of changes. The system also notifies you if the TIE server is added to the ePO - On-prem server after the device is added to Trellix ESM.

Once TIE generates events, you can view their execution history and select the actions to take on the malicious data.

Correlation rules

The system optimizes correlation rules for TIE data. They generate events that you can search and sort through.

  • TIETrellix GTI reputation changed from clean to dirty

  • TIE — Malicious file (SHA-1) found on increasing number of hosts

  • TIE — Malicious file name found on increasing number of hosts

  • TIE — Multiple malicious files found on single host

  • TIETIE reputation changed from clean to dirty

  • TIE — Increase in malicious files found across all hosts

View event rule

View the rule details and the normalization hierarchy of the event selected.

  1. On the Trellix ESM dashboard, select an event form the Events pane.

  2. Click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.pngView Rule to view the event information on the ESM Rules page.

  3. Click Normalization Name to view the normalization taxonomy information of the selected event.

Alarms

Trellix ESM has two alarms that might trigger when the system detects important TIE events.

  • TIE bad file threshold exceeded triggers from the correlation rule TIE - Malicious file (SHA-1) found on increasing number of hosts.

  • TIE unknown file executed triggers from a specific Threat Intelligence Exchange event and adds information to the TIE data source IPs watchlist.

Watchlist

The TIE data source IPs watchlist maintains a list of systems that have triggered the TIE unknown file executed alarm. It is a static watchlist without expiration.