The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Integration with Private GTI Cloud

Prev Next

The McAfee Global Threat Intelligence provides file reputation and IP reputation for files queried by Network Security Platform. McAfee GTI queries threat information from the Network Security Platform Sensors. This helps the engine to learn and accordingly provide reputation scores for the threats. The reputation score is relative and based on all the information from different threat vectors that GTI receives. The reputation score from McAfee GTI helps you to take the necessary corrective actions for the known threats and the emerging threats. The McAfee GTI Public Cloud is enabled by default.

Previously you could configure file reputation using the CLI command set gtiserver ip. The file reputation queries that used DNS queries could be sent to Private GTI cloud.

With release 10.1, you can configure your Private Cloud to provide both IP and file reputation scores to the malware files from the Manager. Network Security Platform Sensors can be configured to send threat information to the Private GTI Cloud instead of the GTI Public Cloud. File reputation and IP reputation scores is retrieved from the private cloud based on which rules and policies to prevent attacks can be configured.

Network Security Platform uses certificate to authenticate the private cloud. The Private Cloud key and certificate are used to establish communication between Network Security Platform and the cloud.

Note

Private GTI Cloud feature is available only in NS-series and Virtual IPS Sensors with Sensor software version 9.2 and later.

The Private GTI Cloud can be integrated from the same page that was available to GTI Public Cloud. To configure the Private GTI Cloud, go to Manager → <Admin Domain Name> → Integration → GTI.

Telemetry

You can configure the telemetry information sent to the McAfee GTI Cloud. When the McAfee GTI Cloud is enabled, information about alerts, features, Sensor version, Manager version and others are sent to the GTI cloud. You can view the details sent to the GTI Cloud from the Manager.

In release 9.1 and before, the telemetry information sent to the McAfee GTI Cloud could be viewed in the GTI integration page under Manager → <Admin Domain Name> → Integration → GTI. With this release 10.1, the telemetry information can be viewed under Manager → <Admin Domain Name> → Setup → Telemetry. The options to configure the information sent to McAfee GTI Cloud remains the same.