The benefits of McAfee EIA are as follows:
- Provides visibility into the executables used in the enterprise network
- Provides file information for non-executables like doc and pdf files on an endpoint
- Provides characteristics of the executable such as the version, the endpoints where it was executed, the number of connections made, the applications invoked, and the events associated with it
- Provides reputation (malware confidence) for each executable and data file using its own malware indicators and dynamic analysis engine
- Provides trust information for good and unknown executables
- Enables detection of unknown executables in the network that the administrator can classify as allowed or blocked, thereby creating an intelligent baseline for the network
- Provides the administrator the flexibility to enable auto-classification of known good executables as allowed and known bad executables as blocked
- Integrates with the IPS Sensor's Allow and Block Lists functionality to prevent further spread of malware in the network
- Provides correlation between the Application Identification feature provided by the IPS Sensor with the executable information for every flow
- Correlates McAfee EIA executable information with analysis from other network detections such as Intelligent Sandbox and NTBA.