This section provides the high-level steps to integrate NTBA Appliance with EIA.
Set up Trellix Agent with ePolicy Orchestrator - On-premises : Deploy Trellix Agent extension and Trellix Agent package to the ePolicy Orchestrator - On-premises server. Skip this step if you have deployed Trellix Agent version 4.8 or higher.
Set up EIA with ePolicy Orchestrator - On-premises : Deploy the Endpoint Intelligence Management extension and EIA package to the ePolicy Orchestrator - On-premises server. Assign policy to managed systems for EIA to communicate with the NTBA Appliance.
Enable EIA integration on the Manager: Establish connections between the NTBA appliance and the managed host systems with the EIA by enabling EIA integration at the Global level or the Device level on the Manager. The Auto-Classification Settings are available only at the Global level.
Note
Maximum endpoint connections supported on the NTBA Appliance is 12000.
Work with allow and block lists: You can either enable the auto-classification settings or manually change the executable classification. The manually classified values of the executable hashes are added to the allowed/blocked hashes that the administrator maintains.
Configure NTBA policies for EIA alerts: There are seven attack definitions for the NTBA policies. Based on which of the alerts you want to see, you can configure policies to raise only those EIA alerts.
View executables running on endpoints: You can view all the executables running on your internal endpoints that have made network calls on the Endpoint Executables page. The top endpoint executables are displayed in the Top Endpoint Executables monitor on the Home Dashboard page.
Analyze executable behavior: Even with auto-classification settings enabled, there might be instances where the executable classification is not justified with its behavior. In such cases, you might want to investigate these executables and accordingly change the executable classification as allowed or blocked so they appear with the modified value next time. The changes are updated to the allowed and blocked hashes maintained by the Manager. You can also generate reports to see more details on the top 10 endpoint executables and endpoint executable connections.
Note
Quarantine of endpoints is not supported.