You can enable Intelligent Sandbox to collect the Enterprise and Trellix GTI / Reputation data from the server through the channel.
When the channel is enabled and the Trellix GTI / Reputation is configured in the analyzer profile, Intelligent Sandbox does a file reputation lookup, using Trellix GTI or Enterprise Reputation, for the submitted samples through the channel. If the administrator configures Enterprise Reputation on , the Threat Analysis Report shows the Enterprise Reputation severity score. If not set, the Trellix GTI file reputation fetched from the server is displayed in the Threat Analysis Report.
Receive External Reputation from - Currently, we support reputation from MWG and ATD. If the file hashes were previously unseen in TIE Server and known Malicious from ATD/MWG, adds it to its database.
Severity | Threat Level Mapping |
|---|---|
unverified | Informational |
low | Informational |
very low | Informational |
medium | Malicious |
high | Malicious |
very high | Malicious |
Severity | Threat Level Mapping |
|---|---|
Medium (3) | TIE File Reputation (ATD) |
High (4) | TIE File Reputation (ATD) |
Very high (5) | TIE File Reputation (ATD) |
Severity | Threat Level Mapping |
|---|---|
1-30 | TIE File Reputation (MWG) |
31-70 | TIE File Reputation (MWG) |
71-100 | TIE File Reputation (MWG) |