The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring NTBA policies for EIA alerts

Prev Next

Seven attack definitions are added to the NTBA policies in Policy → Network Threat Behavior Analysis → NTBA Policies:

NTBA policy

Description

Enabled by default

Alert frequency

EXECUTABLE: Unclassified executable detected by Endpoint Intelligence Agent engine

This alert is raised when the executable is not classified by the administrator or is not auto-classified.

No

Raised once per executable from the NTBA Appliance

EXECUTABLE: Allowed executable detected by Endpoint Intelligence Agent engine

This alert is raised when the executable is marked as allowed by the administrator.

This alert is also raised when the executable is found to be digitally allowed or GTI allowed.

No

EXECUTABLE: Blocked executable detected by Endpoint Intelligence Agent engine

This alert is raised when the executable is marked as blocked by the administrator or when the executable is auto-classified based on GTI Block List.

Yes

Raised per executable per endpoint

MALWARE: Very High-confidence malware executable detected by Endpoint Intelligence Agent engine

This alert is raised when the malware confidence of the executable detected by EIA is very high and the executable is not allowed.

Yes

MALWARE: High-confidence malware executable detected by Endpoint Intelligence Agent engine

This alert is raised when the malware confidence of the executable detected by EIA is high and the executable is not allowed.

Yes

MALWARE: Medium-confidence malware executable detected by Endpoint Intelligence Agent engine

This alert is raised when the malware confidence of the executable detected by EIA is medium and the executable is not allowed.

No

MALWARE: Very High-confidence malware file detected by Endpoint Intelligence Agent engine

This alert is raised when the malware confidence of the file detected by EIA is very high and the file is not allowed.

No

Raised per non-executable file such as doc or pdf file per endpoint

Depending on which of the attack definitions are enabled in the NTBA policies, alerts are generated for the matching traffic.

The malware attacks can be viewed in the Top Malware Files monitor on the Manager Dashboard page, and the Top Attack Executables table in the Threat Explorer.

Alert throttling

Run set endpointintelligence alertinterval CLI command to configure the time interval as to when the alert should be raised again. By default, it is 7 days. It can be configured between 0 and 30 days. Configure it as zero to disable alert throttling. Whenever a given executable property changes (malware confidence or classification), the alert generation interval is reset for that executable.

Note

Filter functionality is not supported for Endpoint Intelligence Agent alerts.