The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How the integration works

Prev Next

One server or a collection of servers acts as the Threat Intelligence Exchange server. ePO - On-prem is provided with details of the Threat Intelligence Exchange server. The Threat Intelligence Exchange server connects to DXL, which facilitates real-time context sharing between products such as Trellix IPS. Within the Trellix IPS, the Sensor is integrated with DXL. Trellix Agent and the DXL client are bundled with the Sensor software. When the Sensor is integrated with DXL and ePO - On-prem, the client receives information about the location of DXL brokers through ePO - On-prem. A network of DXL brokers constitutes the DXL framework which connects to the Threat Intelligence Exchange server.

Threat Intelligence Exchange deployment scenario
Threat Intelligence Exchange deployment scenario


The integration between Trellix IPS and Threat Intelligence Exchange works in the following sequence:

Threat Intelligence Exchange flow
Threat Intelligence Exchange flow


  • It begins when the Sensor detects a file in the network, computes its file hash, and recognizes that it is suspicious or one that warrants analysis. Whether or not a file is suspicious is determined by first looking up the Manager allow list, then the Manager block list.

  • If the file hash is not present in either of these lists, the Sensor queries the Threat Intelligence Exchange server with the file hash through the DXL framework if DXL integration is enabled.

    • If DXL integration is not enabled, the Sensor queries Global Threat Intelligence using a HTTPS query.

  • Threat Intelligence Exchange receives file reputation for a specific file hash from four different sources. Each of these sources is called a Provider.

    • It receives an Enterprise file reputation which is assigned in ePO - On-prem by a network administrator.

    • It receives an Intelligent Sandbox file reputation based on static and dynamic analyses.

    • It receives a Global Threat Intelligence file reputation.

    • It receives file reputation from an External Provider.

  • The Threat Intelligence Exchange server forwards this file reputation to the Sensor through the DXL framework.

  • Depending on the advanced malware policy configuration, the Sensor raises an alert or takes other configured action. The alert displays the file reputation with the following details that are also received from Threat Intelligence Exchange.

    • Provider – Enterprise, Intelligent Sandbox, Global Threat Intelligence, or External Provider. The table lists the details provided by each of these providers.

      Provider

      Detail – Description

      Enterprise

      Total detections – The number of detections this file hash has triggered

      Last detection – The last time a detection was triggered by this file hash

      Distinct file names used by this file – The number of distinct filenames this hash has been detected to be using

      Malware confidence observed for this file – As assigned by the network administrator in ePO - On-prem

      Intelligent Sandbox

      Overall malware confidence – As computed by Intelligent Sandbox

      Individual engine malware confidence

      • Gateway Anti-Malware Engine

      • Anti-Malware Engine

      • Sandbox

      Malware confidence for each of the individual engines

      Global Threat Intelligence

      Malware confidence – As stored in Global Threat Intelligence

      External Provider

      Malware confidence – As stored in the external file reputation provider