The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Best practices

Prev Next

The auto-classification settings for allow list executables (based on GTI reputation or signed by a trusted authority) are enabled by default. Auto-classification for block list executables based on GTI reputation and dynamic analysis are disabled by default. Trellix recommends that you keep all auto-classification settings as enabled unless you want to investigate every executable manually.

For all executables, the malware confidence displayed on the Manager is a best effort based on malware indicators associated with each executable.

If time permits:

  • Once the solution is deployed, learn the executables used in the network to create a baseline computer profile, investigate, and classify as allowed all the approved executables for your enterprise.
  • Every time new patches are deployed, use the endpoint baseline generator to create an updated hash list and import into the Manager.
  • Investigate each executable that displays malware confidence as low or very low. For example, use the malware indicators, alerts generated, and network forensics.
  • Integrate with Trellix Intelligent Sandbox to leverage its sandboxing capabilities.
  • Enable the Gateway Anti-Malware Engine running on NTBA as an additional engine for inspection of malware.
  • Look at the number of endpoints using an executable, the type of applications, and events associated with the executable.
  • If the number of endpoints is high, it is unlikely that it is a bot.

Analyze the results from all of these, and then make the final decision to allow list or block list an executable. If you have time constraints, investigate executables that have malware confidence displayed as medium and above.