The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Recommended workflow

Prev Next

Assess, prioritize, analyze, and react against threats using the TIE services activities in Trellix ePO - On-prem.

We provide a brief introduction and overview of each activity. See KB86307 for details about each activity.

For an effective use of TIE services capabilities, follow a repeatable and scalable workflow to prioritize and analyze high impact or prevalent threats in the managed environment.

  1. Assessing — The dashboards for TIE Server Files or TIE Server Certificates quickly assess the health status of the environment.

    From the Custom menu you add a new dashboard and specify a name and its visibility.

    Navigate: To create a custom dashboard, Dashboards → Dashboards Actions → Custom → Add.

  2. Prioritizing — The default filters and the Query and Reports system in Trellix ePO - On-prem determine which files or certificates are a priority for analysis.

    Navigate: TIE Reputations → File Search → Custom, or TIE Reputations → Certificate Search → Custom.

  3. Analyzing — It presents the list of associated files or certificates, their parent files or certificates, where they were run, and their details including behavioral attributes.

    Navigate: TIE Reputations → TIE Files Reputations, then select an option. Navigate to TIE Certificate Reputations, then select an option.

  4. Reacting — The manual overrides handle existing malware and protect the environment against future executions. The Trellix ePO - On-prem can list queries for the systems that were tagged as compromised.

    Navigate: TIE Reputations → File Search → Actions → System Health Indicator → Set Possibly Compromised