You can use Trellix ePO - On-prem to configure, manage, deploy, and enforce Adaptive Threat Protection policies. Once configured, you can then use queries and dashboards to monitor your environment for threats.
Components
Adaptive Threat Protection can integrate with these components:
TIE server — A server that stores information about file and certificate reputations, then passes that information to other systems.
Trellix DXL — Clients and brokers that enable bidirectional communication between the Adaptive Threat Protection module on the managed system and the TIE server.
Threat Prevention is mandatory to install Adaptive Threat Protection.
How Adaptive Threat Protection works
Adaptive Threat Protection functions differently, depending on whether TIE server is deployed:
If the TIE server isn't present and the system is connected to the Internet, Adaptive Threat Protection uses Trellix GTI for reputation decisions.
If the TIE server isn't present and the system isn't connected to the Internet, Adaptive Threat Protection determines the file reputation using information available locally.
If the TIE server is present, Adaptive Threat Protection uses the Trellix DXL framework to share file and threat information instantly across the whole enterprise.