The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing threat reputations on the Trellix TIE server database

Prev Next

Based on the settings in the TIE server policies, allow, block, or require user action for the file and certificate reputations used in your environment. You can fine-tune what is allowed or blocked by overriding default reputation settings for specific files and certificates.

File and certificate reputations are added to the TIE server database in four ways.

  • Running the TIE client module Threat Prevention or Endpoint Security Adaptive Threat Protection 10.5.

  • Intelligent Sandbox and Web Gateway send reputation information over the Trellix DXL framework which is added to the database.

  • TIE Server polls Intelligent Virtual Execution (IVX) or IVX Cloud for the results of files submitted for sandboxing.

  • External Reputation provider through OpenDXL.

  • Manually import files or certificates to the database.