The benefits of EIA are as follows:
Provides visibility into the executables used in the enterprise network
Provides file information for non-executables like doc and pdf files on an endpoint
Provides characteristics of the executable such as the version, the endpoints where it was executed, the number of connections made, the applications invoked, and the events associated with it
Provides reputation (malware confidence) for each executable and data file using its own malware indicators and dynamic analysis engine
Provides trust information for good and unknown executables
Enables detection of unknown executables in the network that the administrator can classify as allowed or blocked, thereby creating an intelligent baseline for the network
Provides the administrator the flexibility to enable auto-classification of known good executables as allowed and known bad executables as blocked
Integrates with the IPS Sensor's Allow and Block Lists functionality to prevent further spread of malware in the network
Provides correlation between the Application Identification feature provided by the IPS Sensor with the executable information for every flow
Correlates EIA executable information with analysis from other network detections such as Intelligent Sandbox and NTBA.