The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Building file prevalence and observing

Prev Next

You can see what is running in your environment and add file and certificate reputation information to the TIE services database. This information also populates the graphs and dashboards in ePO - SaaS where you view detailed information about files and certificates.

To get started, create one or more TI ENS policies to run on a few systems in your environment. The policies determine:

  • When a file or certificate with a specific reputation is allowed to run on a system

  • When a file or certificate is blocked

  • When the user is prompted for what to do

  • When a file is submitted to Intelligent Sandbox, IVX or IVX Cloud for further analysis

While building file prevalence, you can run the policies in Observation mode. File and certificate reputations are added to the database but no action is taken. You can see what the TIE services block or allow if the policy is enforced.