One server or a collection of servers acts as the Threat Intelligence Exchange server. Trellix ePO - On-prem is provided with details of the Threat Intelligence Exchange server. The Threat Intelligence Exchange server connects to DXL, which facilitates real-time context sharing between products such as Trellix IPS. Within the Trellix IPS, the Sensor is integrated with DXL. Trellix Agent and the DXL client are bundled with the Sensor software. When the Sensor is integrated with DXL and Trellix ePO - On-prem, the client receives information about the location of DXL brokers through Trellix ePO - On-prem. A network of DXL brokers constitutes the DXL framework which connects to the Threat Intelligence Exchange server.

The integration between Trellix IPS and Threat Intelligence Exchange works in the following sequence:

- It begins when the Sensor detects a file in the network, computes its file hash, and recognizes that it is suspicious or one that warrants analysis. Whether or not a file is suspicious is determined by first looking up the Manager allow list, then the Manager block list.
- If the file hash is not present in either of these lists, the Sensor queries the
Threat Intelligence Exchange server with the file hash through the DXL framework if DXL integration is enabled.
- If DXL integration is not enabled, the Sensor queries Global Threat Intelligence using a HTTPS query.
- Threat Intelligence Exchange receives file reputation for a specific file hash from three different sources. Each of these sources is called a
Provider.
- It receives an Enterprise file reputation which is assigned in Trellix ePO - On-prem by a network administrator.
- It receives an Intelligent Sandbox file reputation based on static and dynamic analyses.
- It receives a Global Threat Intelligence file reputation.
- The Threat Intelligence Exchange server forwards this file reputation to the Sensor through the DXL framework.
- Depending on the advanced malware policy configuration, the Sensor raises an alert or takes other configured action. The alert displays the file reputation with the following details that are also received from
Threat Intelligence Exchange.
- Provider – Enterprise,
Intelligent Sandbox, or
Global Threat Intelligence. The table lists the details provided by each of these providers.
Provider Detail – Description Enterprise Total detections – The number of detections this file hash has triggered Last detection – The last time a detection was triggered by this file hash Distinct file names used by this file – The number of distinct filenames this hash has been detected to be using Malware confidence observed for this file – As assigned by the network administrator in Trellix ePO - On-prem Intelligent Sandbox Overall malware confidence – As computed by Intelligent Sandbox Individual engine malware confidence - Gateway Anti-Malware Engine
- Anti-Malware Engine
- Sandbox
Malware confidence for each of the individual engines Global Threat Intelligence Malware confidence – As stored in Global Threat Intelligence
- Provider – Enterprise,
Intelligent Sandbox, or
Global Threat Intelligence. The table lists the details provided by each of these providers.