The Sensor creates a fingerprint (MD5 hash value) of the file that is seen as potentially malicious, embeds the fingerprint in a standard HTTPS request, and sends it to GTI cloud server. The cloud server compares the fingerprint against the threat database maintained by Trellix Labs. If the fingerprint is identified as a known malware, the cloud server notifies the Sensor and it enforces a response action for the malware. Note that the details of the malware can be viewed from the Attack Log.
GTI fingerprints
- Published on Sep 21, 2026
- 1 minute(s) read
Was this article helpful?