This section provides the high-level steps to integrate NTBA Appliance with
McAfee EIA.
Task
- Set up Trellix Agent with ePolicy Orchestrator - On-prem: Deploy Trellix Agent extension and Trellix Agent package to the ePolicy Orchestrator - On-prem server. Skip this step if you have deployed Trellix Agent version 4.8 or higher.
- Set up McAfee EIA with ePolicy Orchestrator - On-prem: Deploy the Endpoint Intelligence Management extension and McAfee EIA package to the ePolicy Orchestrator - On-prem server. Assign policy to managed systems for McAfee EIA to communicate with the NTBA Appliance.
-
Enable EIA integration on the Manager: Establish connections between the NTBA appliance and the managed host systems with the
McAfee EIA by enabling EIA integration at the
Global level or the
Device level on the Manager. The
Auto-Classification Settings are available only at the
Global level.
Note
Maximum endpoint connections supported on the NTBA Appliance is 12000.
- Work with allow and block lists: You can either enable the auto-classification settings or manually change the executable classification. The manually classified values of the executable hashes are added to the allowed/blocked hashes that the administrator maintains.
- Configure NTBA policies for McAfee EIA alerts: There are seven attack definitions for the NTBA policies. Based on which of the alerts you want to see, you can configure policies to raise only those EIA alerts.
- View executables running on endpoints: You can view all the executables running on your internal endpoints that have made network calls on the Endpoint Executables page. The top endpoint executables are displayed in the Top Endpoint Executables monitor on the Home Dashboard page.
-
Analyze executable behavior: Even with auto-classification settings enabled, there might be instances where the executable classification is not justified with its behavior. In such cases, you might want to investigate these executables and accordingly change the executable classification as allowed or blocked so they appear with the modified value next time. The changes are updated to the allowed and blocked hashes maintained by the Manager. You can also generate reports to see more details on the top 10 endpoint executables and endpoint executable connections.
Note
Quarantine of endpoints is not supported.