The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Understanding executable classification

Prev Next

The Manager provides options to auto-classify or manually classify the executables. Executables that appear as unclassified can be allowed or blocked. The Manager pushes the updates in the allowed and blocked hashes to the NTBA Appliance every five minutes.

The executables are classified as the following:

  • Allowed: Executables that are considered safe
  • Blocked: Executables that are not considered safe or not allowed per corporate policy
  • Unclassified: Executables that are yet to be classified

You can classify executables from any of the following:

  • Endpoint Baseline Generator: When the Endpoint Baseline Generator tool is run on a computer, it scans the computer, calculates the heuristics for all the executable hashes on the system, and generates an XML file. This XML file contains information, such as file name, file size, hash type (MD5), and file hash.

    Trellix recommends that you run the tool on a system that can be treated as a baseline computer profile for your organization. You can then use the import option in the Manager to append your list to the existing allow and block list in the Manager.

  • Auto-Classification: You can configure Auto-Classification Settings at the Global level of the EIA Integration page to classify executables based on the following:
    • If the executable is signed and trusted, it is allowed.
    • If GTI file reputation is malicious, it is blocked.
    • If GTI file reputation is clean, it is allowed.
    • If dynamic analysis reports an executable or data file as malicious, it is blocked.
    • Auto-classified blocked and allowed executables are added to the Allowed and Blocked Hashes tabs in File Hashes page.

    Note

    Make sure that GTI is reachable. This can be done by configuring the local DNS Server (or proxy) by selecting Devices → <Admin Domain Name> → Global → Default Device Settings → Common → Name Resolution. Enter the IP Address (IPv4 or IPv6) here.

  • Manual Classification: You can also manually classify the executables from the Manager. Based on their overall malware confidence and their network behavior, you can classify them as allowed or blocked.

    Note

    Manual classification has the highest priority and takes precedence over auto-classification.

The following aspects are used to classify executables:

Executable classification
Manually allowed Manually blocked Digitally trusted Dynamic analysis Auto-GTI allowed Auto-GTI blocked Gets classified as
Yes - Yes or No Any Yes or No Yes or No Allowed
- Yes Yes or No Any Yes or No Yes or No Blocked
Not classified Yes Any Yes or No Yes or No Allowed
Not classified No Malicious Yes or No Yes or No Blocked
Not classified No Not malicious Yes No Allowed
Not classified No Not malicious No Yes Blocked
Scenario: A new executable is seen in your network
- Yes Any Unknown Allowed
- No Malicious Unknown Blocked
- No Not malicious Unknown Unclassified

Note

A new executable is not known to Trellix GTI and an administrator cannot classify it until its behavior is analyzed. For the second occurrence, GTI discovers and computes reputation for an unclassified executable, and the NTBA classification may vary accordingly.