The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How the integration works

Prev Next

One server or a collection of servers acts as the Threat Intelligence Exchange server. Trellix ePO - On-prem is provided with details of the Threat Intelligence Exchange server. The Threat Intelligence Exchange server connects to DXL, which facilitates real-time context sharing between products such as Trellix IPS. Within the Trellix IPS, the Sensor is integrated with DXL. Trellix Agent and the DXL client are bundled with the Sensor software. When the Sensor is integrated with DXL and Trellix ePO - On-prem, the client receives information about the location of DXL brokers through Trellix ePO - On-prem. A network of DXL brokers constitutes the DXL framework which connects to the Threat Intelligence Exchange server.

Threat Intelligence Exchange deployment scenario


The integration between Trellix IPS and Threat Intelligence Exchange works in the following sequence:

Threat Intelligence Exchange flow


  • It begins when the Sensor detects a file in the network, computes its file hash, and recognizes that it is suspicious or one that warrants analysis. Whether or not a file is suspicious is determined by first looking up the Manager allow list, then the Manager block list.
  • If the file hash is not present in either of these lists, the Sensor queries the Threat Intelligence Exchange server with the file hash through the DXL framework if DXL integration is enabled.
    • If DXL integration is not enabled, the Sensor queries Global Threat Intelligence using a HTTPS query.
  • Threat Intelligence Exchange receives file reputation for a specific file hash from three different sources. Each of these sources is called a Provider.
    • It receives an Enterprise file reputation which is assigned in Trellix ePO - On-prem by a network administrator.
    • It receives an Intelligent Sandbox file reputation based on static and dynamic analyses.
    • It receives a Global Threat Intelligence file reputation.
  • The Threat Intelligence Exchange server forwards this file reputation to the Sensor through the DXL framework.
  • Depending on the advanced malware policy configuration, the Sensor raises an alert or takes other configured action. The alert displays the file reputation with the following details that are also received from Threat Intelligence Exchange.
    • Provider – Enterprise, Intelligent Sandbox, or Global Threat Intelligence. The table lists the details provided by each of these providers.
      Provider Detail – Description
      Enterprise Total detections – The number of detections this file hash has triggered
      Last detection – The last time a detection was triggered by this file hash
      Distinct file names used by this file – The number of distinct filenames this hash has been detected to be using
      Malware confidence observed for this file – As assigned by the network administrator in Trellix ePO - On-prem
      Intelligent Sandbox Overall malware confidence – As computed by Intelligent Sandbox
      Individual engine malware confidence
      • Gateway Anti-Malware Engine
      • Anti-Malware Engine
      • Sandbox
      Malware confidence for each of the individual engines
      Global Threat Intelligence Malware confidence – As stored in Global Threat Intelligence