The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sample scenario: Analyze an unclassified executable with high malware confidence

Prev Next

Consider an executable, DAP.exe, is shown on the Top Endpoint Executables monitor with malware confidence as High and classification as Unclassified. This section provides you a workflow that you could follow in the Manager user interface to further investigate the executable properties, malware indicators used to compute the malware confidence, the type of alerts it triggered, the confidence assigned by other malware engines to this file, and subsequently allow or block it.

Steps:

  1. Click Dashboard on the Home page to view the Top Endpoint Executables monitor.

    1. Select Attacks to view executables that have generated most attacks.

      -OR-

      Select Endpoints (default) to view executables that have made most connections. The Device drop-down list is shown when you select Endpoints. This list shows all NTBA Appliances configured that have EIA services running on them sorted in alphabetical order.

    2. Click DAP.exe in the Top Endpoint Executables monitor to go the Endpoint Executables page.

      Note

      Hover the mouse on the bar graph to see the executable name, number of attacks/endpoints, executable hash name, classification type, and malware confidence level.

      The executable, DAP.exe, shows high malware confidence but the classification type is shown as Unclassified.

  2. The Endpoint Executables page provides network visibility on how many endpoints are running the executables, how many connections were made, and the events that it triggered. It also displays the malware indicators used to compute the malware confidence of the executable.

    1. Click the Hash link, IP Address link, Application link, Attack link, Attacker IP Address link, or Target IP Address link in the Details panel to go to the Threat Explorer page.

    Note

    In some cases, alert count is shown even for allowed executables such as Mozilla Firefox. If bad or malicious sites were accessed and files downloaded using Mozilla Firefox, there could be executables generating alerts that result in increase of the attack count.

  3. Click View Attacks in the Threat Explorer page to go to the Malware Files page to view the malware confidence alerts, how the malware confidence was computed by the individual malware engines, and overall malware confidence of the executable was computed. This page also allows an in-depth analysis of the malware detected in your network.

    Note

    You can also go to the Malware Files page from the Endpoint Executables page.

    Note

    For alerts triggered by EIA, the bottom panel displays the Direction and Protocol as unknown, Attacker Country and Target Country as blank, and Result as inconclusive.

  4. Select Analysis → Network Forensics to further analyze the endpoint behavior on your network.

    1. Enter the IP address of the endpoint for the selected date and time and click Analyze.

      The Network Forensics page is displayed with summary, conversation, and event information.

      Note

      All the executables invoked on the endpoint are displayed in the Client connections panel.

    2. Scroll to the Top 10 Conversations panel to see the connections made using this IP address.

    3. Scroll to the Last 50 Events to view more details about the attacks. The Endpoint Executables column displays hash, name, classification, and malware confidence. Click the hash link to go to the Threat Explorer page.

  5. Click View attacks in the Attack Log to view and analyze alerts.

    1. You can view and group by alerts based on the following:

      • Name: Displays binary name of the executable

      • Hash: Displays the file hash of the executable

      • Malware Confidence: Displays the malware confidence level returned by the configured EIA. The malware confidence values are very high, high, medium, low, very low, and unknown.

      Note

      All the executables invoked on the endpoint are displayed in the Client connections panel.

      Note

      The above-mentioned fields are not displayed for suppressed alerts.

      The alert count and attack count are displayed for the attribute selected in the list.

    2. Double-click an alert to open the Alert details panel.

      For all alerts triggered by EIA, an additional panel called Endpoint Intelligence panel is displayed. This displays the hash, name, classification, and malware confidence of the executable.

    3. Click Real-time EIA Details to view executable information for existing IPS and NTBA alerts that have 5-tuple information. Alerts, such as Exploits, Callback Activity, Behavioral, Malware, and Policy violation, have the 5-tuple information. It also gives information of the library invoked by the executable, the malware indicators used to compute the score, and classifier information.

      As an administrator, you might want to investigate the alerts further.

    Note

    The malware confidence and classification values shown in the Real-time EIA Details window might be different from what is shown in the Alert Details window. This is because the Alert Details window shows the malware confidence and classification of the alert when it is first generated while the Real-time EIA Details shows the current details of the executable.

  6. Based on the analysis, you can classify the executable as allowed or blocked by clicking the Take Action link on the Malware Files page.

    These updates are made to the allowed and blocked hashes maintained in the Manager.

    The Manager sends the changes in the allowed and blocked hashes to the NTBA Appliance every five minutes. Whenever the file's hash matches with the ones in the allowed and blocked hashes, the allowed hashes are exempted from malware analysis.