Since the Sensor receives file reputation for a file from four different sources, it must choose the one that is most relevant to the security requirements of your network. To do this, the Sensor assigns varying importance to each of the four providers.
First preference is given to the Enterprise malware confidence since it is specific to this environment.
Second preference is given to the Trellix Intelligent Sandbox since it is configured in your policy and might carry out static and dynamic analysis if they are enabled in the appliance.
Third preference is given to Global Threat Intelligence.
Fourth preference is given to the external file reputation provider.
After the Sensor has selected the appropriate score, it is displayed in the Manager. You can view this score in several pages in the Manager. One of the pages where you are able to see it mapped to the appropriate engine is the Malware Files page under the TIE / GTI File Reputationcolumn. For more details on viewing detected threats in the Manager, refer to the Trellix Intrusion Prevention System Product Guide.