The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Details of how the integration works

Prev Next

Following is the procedure and process flow when the integration with Trellix Intelligent Sandbox involves a standalone Sensor and Manager.

Note

Trellix GTI File Reputation is available both in the Advanced Malware policies of Trellix IPS as well as in Trellix Intelligent Sandbox. Trellix recommends that you enable Trellix GTI File Reputation in both Trellix IPS and Trellix Intelligent Sandbox. The Sensor can respond quicker if it is configured in the Advanced Malware policy because, in this case, it directly communicates with Trellix GTI.

  1. You configure Trellix Intelligent Sandbox integration details for the required Sensor.

  2. You enable the Intelligent Sandbox as one of the malware engines in the corresponding Advanced Malware policy. For the sake of explanation, assume that you have enabled all the engines except NTBA for all the file types.

    Note

    Based on which engine reports back first, the IPS Sensor takes the response action. Consider that you have configured high-severity malware to be blocked by the Sensor. Trellix GTI File Reputation configured in Trellix IPS reports a file as high-severity malware. Then, the Sensor blocks this file even before receiving the results from the Intelligent Sandbox engine.

  3. You have applied this Advanced Malware policy to the required inline ports.

    Note

    The Intelligent Sandbox malware engine can be used with SPAN and tap ports. However, similar to other malware engines, response actions, such as Block and Send TCP Reset, might not have the desired effect since the file might have reached the target host.

  4. If the Sensor detects a supported file type being transferred over HTTP or SMTP (encoded using Base64 only), it extracts the file and checks it against its allow list and then its block list.

  5. Assume that the file's hash value is not listed in the Sensor's allow or block list. The Sensor constantly streams the file, as the user downloads it, to all the other engines for a concurrent analysis. The Sensor holds the last packet from the user for a specific time period, while it awaits the results from any of the configured malware engines.

  6. From the analyzer profile configured in the respective Trellix IPS user profile, Trellix Intelligent Sandbox determines the analysis methods and the reports to be generated.

    • If Trellix Intelligent Sandbox responds with a malware score that meets the Action Thresholds for alerting in the Advanced Malware policy, the Sensor raises Malware: Malicious file detected by Trellix Intelligent Sandbox alert and takes the other configured response actions.

    • If Trellix Intelligent Sandbox responds with a malware score that does not meet the Action Thresholds, the Sensor raises an informational alert Malware: Unknown file download detected and submitted to Trellix Intelligent Sandbox for analysis. As expected, no response actions are taken. If the file is determined to be clean, the Manager deletes this alert. If there is any change in the malware score, the Manager updates the same alert.

    Note

    As mentioned earlier, the Manager uses the user name and password defined in nsp profile to establish its communication with Trellix Intelligent Sandbox. The Manager also allows different Sensors to have their own analyzer profile as configured by the respective Sensor users.

    Recall that Trellix Intelligent Sandbox must respond within the file scan timeout for the Sensor to function as explained above.

  7. Trellix IPS performs malware analysis on files in the following sequence:

    • Virtual IPS: Threat Feed / Local Block List → TIE/GTI File Reputation → Trellix IPS Analysis → Trellix Intelligent Sandbox or NTBA (if Trellix Intelligent Sandbox is disabled)

    • NS-series: Threat Feed / Local Block List → TIE/GTI File Reputation → Trellix IPS Analysis → Gateway Anti-Malware → Trellix Intelligent Sandbox

  8. The Manager continuously queries Trellix Intelligent Sandbox for the results of this analysis. When the reports are received, the Manager updates the record in the Malware Files page.

  9. Since, dynamic analysis is a time taking process, there is a need to carefully employ this process for improved user experience. Trellix IPS submits files to Trellix Intelligent Sandbox for dynamic analysis only if the other engines enabled report back the malware confidence as medium or above.

  10. Assume that the results of dynamic analysis indicate that the file is malicious with a high severity level. You can now use the Quarantine feature to quarantine the host from the rest of the network until you are sure that the host is safe again.

  11. Because the malware severity is high, Trellix Intelligent Sandbox adds the MD5 hash of this file to its local blacklist. So, the next time this file is submitted by any source, it is able to respond in the shortest possible time.

    Note

    Trellix Intelligent Sandbox adds a file to its blacklist if the malware severity of the file is medium, high, or very high.

  12. If you had configured the Add to Block List action threshold in the Advanced Malware policy, the Manager can include the MD5 hash of this file in the block list of all its Sensors. Therefore, when the same file is detected by any of the Sensors, it is blocked by that Sensor itself. This reduces the chances of such malware entering your network again.

    Note

    In case MD5 entries limit has reached, the Manager adds SHA256 hash value(s) of the malware file(s) to its block list and sends the same hash value(s) to the Sensor through incremental or full update.

    Note

    Trellix recommends that you verify how the Advanced Malware feature works for a period of time, fine-tune it until it functions as expected, and only then enable the Add to Block List action threshold in the Advanced Malware policies.

What happens in case of MDR?

  • You configure the Trellix Intelligent Sandbox in the active Manager. It takes 15 minutes for this configuration to be copied to the standby. Alternatively, you can use the Retrieve Configuration feature in the standby to immediately copy the MDR configuration to the standby.

  • When a Sensor submits a file to Trellix Intelligent Sandbox, it informs both the Managers. So, both the Managers query Trellix Intelligent Sandbox separately for the results of the file.

  • Every 10 minutes, both the Managers cross-check their malware report data from Trellix Intelligent Sandbox and ensure that the data is synchronized.

What happens in case of Sensors in failover?

  • When you configure the integration for the failover Sensors, both the Sensors establish separate communication channels with Trellix Intelligent Sandbox. So, Trellix Intelligent Sandbox considers them to be different users. It sends the update only to the Sensor that submitted the file.

  • The file is extracted only by the Sensor that detected it. If a Sensor goes down within the packet hold time interval, based on the port configuration, the file might be forwarded without malware analysis or dropped.

  • If the Sensor goes down after the packet hold time interval but before the file session time interval, the update from Trellix Intelligent Sandbox is lost since it is sent only to the Sensor that submitted the file.