The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Core attribute

Prev Next

Select the core attribute as Executable Hash and click the hyperlink to view the following details:

Field

Description

View Detections

Takes you to the Malware Files page to view the malware confidence computed by individual engines and the overall malware confidence for the executable

Hash

Displays the file hash. This link takes you to the Threat Explorer with a filter on the hash and the selected time.

Binary Name (type)

Displays the binary name and the type, whether process or library

Product Name

Displays the product name for the executable

Version

Displays the product version number

Malware Confidence

Displays the malware confidence level returned by the configured EIA. The malware confidence values are very high, high, medium, low, very low, and unknown.

Classification

Displays the executable classification whether blocked, allowed, or unclassified

Classified

Displays the method of classification and the timestamp, only for classified executables

Certificate Status

Displays if the certificate is from a trusted CA or not. Valid values for executables are Signed and Signed and Trusted. If the executables are unsigned, the status displays blank.

Certificate Signer

Displays the certificate signer name.

GTI Reputation

Displays the file reputation received from GTI. Valid values are Very Low, Low, Medium, High, Very High, and Unknown.

Malware Indicators

Shows some of the methods that were used to compute the executable reputation.

Invoked Libraries

Lists all libraries (DLLs) invoked by the executable. The DLLs are displayed only if EIA finds the corresponding malware confidence to be greater than or equal to the ePO - On-prem Reputation Threshold value. By default, the ePO - On-prem Reputation Threshold value is Medium.

Note

Invoked libraries are displayed when the executable is a process.

Name

Displays names of the library files invoked by the executable

Hash

Displays the file hash. This link takes you to the Threat Explorer with a filter on the hash and the selected time.

Malware Confidence

Displays the malware confidence level returned by the configured EIA

Select GUID-383F43A8-135F-412C-993B-EBF72234C61E-low.png to navigate to Attack Log and view the alerts that matches the selected endpoint executable.

Important

All the other top N security tables are populated with the data related to the selected core attribute and admin domain.

At any time, you can click GUID-9921E25F-C72C-46B7-B7D1-36E626683925-low.png to leave the selected core attribute and return to the main Threat Explorer page.