The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Terminologies

Prev Next

Sensitivity Level

Malware dirtiness level is the level of malicious content in the malware fingerprint. A very high dirtiness level indicates a known malware.

Sensitivity level indicates the level to which Trellix IPS needs to be sensitive to the malware dirtiness level contained in the responses from File Reputation.

Manager provides five different values for Sensitivity Level - Very Low, Low, Medium, High, and Very High. By default, the Sensitivity Level is Very Low.

When you set the Sensitivity Level as Very Low (the default), the Sensor only responds to the File Reputation fingerprints with a high dirtiness level (known malware). Response action from the Sensor can be alert, block, or both as described earlier.

Detection Type

Defines the type of detection that is required for the malware. You can detect malware using File Reputation alone, or the Custom fingerprints, or both. When you enable both File Reputation detection type and Custom detection type, the latter takes precedence over the former.

Public or Private GTI Server details

IP address or Server name information related to the Public or Private GTI Servers. To communicate with the Public GTI and Private GTI Cloud, you need to configure Public Cloud and Private Cloud Server settings. In both the cases, the Sensor embeds the MD5 hash value of the file in a HTTPS REST JSON Request. File Reputation server sends back HTTPS Responses (which contain information such as Malware dirtiness level) to the Sensor.