The Sensor creates a fingerprint (MD5 hash value) of the file that is seen as potentially malicious, embeds the fingerprint in a standard HTTPS request, and sends it to GTI cloud server. The cloud server compares the fingerprint against the threat database maintained by Trellix Advanced Research Center. If the fingerprint is identified as a known malware, the cloud server notifies the Sensor and it enforces a response action for the malware. Note that the details of the malware can be viewed from the Attack Log.
GTI fingerprints
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?