The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Overview

Prev Next

Most enterprises today face a challenge in understanding executables running on the network. With malware increasing at a rampant pace, it has become imperative for security administrators to understand executables sending traffic on the network. Malware can exploit the network and endpoint's inability to coordinate information/policies. Some malware can name themselves as standard executables and make standard application connections on the network. Such malware cannot be detected by looking at just the endpoint processes or monitoring the network traffic flows in isolation.

Combining information obtained from the endpoints with information in the network can provide security administrators deeper visibility into your enterprise. Trellix Intrusion Prevention System, along with Endpoint Intelligence Agent, provides security administrators insight into what executables are running at endpoints that are linked to the network traffic. You can also view malware status and details for non-executables like doc and pdf files. The administrator can then quickly investigate any unusual executable behavior, classify executables and files running on the network as malicious or safe, and take response actions.

McAfee Endpoint Intelligence Agent (McAfee EIA) is an endpoint solution that provides executable and file information to the NTBA Appliance. It delivers real-time and dynamically analyzed detection results.

When EIA is installed on an endpoint, it monitors the system for execution of all executables irrespective of whether it is making outgoing connections. This helps you to even monitor data files like word and pdf documents. When a connection attempt is made by an executable, EIA sends the executable information to the NTBA over an encrypted channel. Using dynamic analysis, if EIA detects malicious data files, it sends the artifacts to NTBA over a separate channel. It also sends dynamic analysis information in metadata. This gives enough time for the NTBA Appliance to process the executable and artifact information and make it available at policy-decision points before the connection request packet is received.

With this solution, you can view all executables and files used on the endpoint. It also provides the number of endpoints using each executable. All executables and files are classified as known good (allowed), known bad (blocked), or unclassified. For the unclassified executables, the solution provides further malware confidence.

The executable information contains:

  • 5-tuple information, such as source IP address, destination IP address, source port, destination port, and protocol

  • Executable name, full path, and hash of the executable that generated the connection

  • User and operating system information associated with the executable

  • Details, such as MD5 hash value, product version, malware confidence, malware name, certificate signer, malware indicators, and classification details

The file information includes a detailed trace report or artifacts in JSON format. You can view details, such as file version and certificates. When network traffic is generated based on the reputation of the executable file, you can allow or block them.