The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

TrellixThreat Intelligence Exchange integration

Prev Next

Threat Intelligence Exchange verifies the reputation of executable programs on the endpoints connected to these files.

When you add a ePO - On-prem device to Trellix ESM, the system automatically detects if a TIE server is connected to the device. If it is, Trellix ESM starts listening in on the Trellix Data Exchange Layer and logging events.

Note

A delay might occur when Trellix ESM connects to the DXL.

When the system detects a TIE server, the system adds TIE watchlists, data enrichment, and correlation rules automatically and enables TIE alarms. You receive a visual notification, which includes a link to a summary of changes. The system also notifies you if the TIE server is added to the ePO - On-prem server after the device is added to Trellix ESM.

Once TIE generates events, you can view their execution history and select the actions to take on the malicious data.

Correlation rules

The system optimizes correlation rules for TIE data. They generate events that you can search and sort through.

  • TIE — Trellix GTI reputation changed from clean to dirty

  • TIE — Malicious file (SHA-1) found on increasing number of hosts

  • TIE — Malicious file name found on increasing number of hosts

  • TIE — Multiple malicious files found on single host

  • TIE — TIE reputation changed from clean to dirty

  • TIE — Increase in malicious files found across all hosts

View event rule

View the rule details and the normalization hierarchy of the event selected.

  1. On the Trellix ESM dashboard, select an event form the Events pane.

  2. Click GUID-90CC508D-C258-41AB-9D9C-4E1D7DE5FBCB-low.png → View Rule to view the event information on the ESM Rules page.

  3. Click Normalization Name to view the normalization taxonomy information of the selected event.

Alarms

Trellix ESM has two alarms that might trigger when the system detects important TIE events.

  • TIE bad file threshold exceeded triggers from the correlation rule TIE - Malicious file (SHA-1) found on increasing number of hosts.

  • TIE unknown file executed triggers from a specific Threat Intelligence Exchange event and adds information to the TIE data source IPs watchlist.

Watchlist

The TIE data source IPs watchlist maintains a list of systems that have triggered the TIE unknown file executed alarm. It is a static watchlist without expiration.