The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Benefits

Prev Next

The benefits of EIA are as follows:

  • Provides visibility into the executables used in the enterprise network

  • Provides file information for non-executables like doc and pdf files on an endpoint

  • Provides characteristics of the executable such as the version, the endpoints where it was executed, the number of connections made, the applications invoked, and the events associated with it

  • Provides reputation (malware confidence) for each executable and data file using its own malware indicators and dynamic analysis engine

  • Provides trust information for good and unknown executables

  • Enables detection of unknown executables in the network that the administrator can classify as allowed or blocked, thereby creating an intelligent baseline for the network

  • Provides the administrator the flexibility to enable auto-classification of known good executables as allowed and known bad executables as blocked

  • Integrates with the IPS Sensor's Allow and Block Lists functionality to prevent further spread of malware in the network

  • Provides correlation between the Application Identification feature provided by the IPS Sensor with the executable information for every flow

  • Correlates EIA executable information with analysis from other network detections such as Intelligent Sandbox and NTBA.