The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Understanding executable classification

Prev Next

The Manager provides options to auto-classify or manually classify the executables. Executables that appear as unclassified can be allowed or blocked. The Manager pushes the updates in the allowed and blocked hashes to the NTBA Appliance every five minutes.

The executables are classified as the following:

  • Allowed: Executables that are considered safe

  • Blocked: Executables that are not considered safe or not allowed per corporate policy

  • Unclassified: Executables that are yet to be classified

You can classify executables from any of the following:

  • Endpoint Baseline Generator: When the Endpoint Baseline Generator tool is run on a computer, it scans the computer, calculates the heuristics for all the executable hashes on the system, and generates an XML file. This XML file contains information, such as file name, file size, hash type (MD5), and file hash.

    Trellix recommends that you run the tool on a system that can be treated as a baseline computer profile for your organization. You can then use the import option in the Manager to append your list to the existing allow and block list in the Manager.

  • Auto-Classification: You can configure Auto-Classification Settings at the Global level of the EIA Integration page to classify executables based on the following:

    • If the executable is signed and trusted, it is allowed.

    • If GTI file reputation is malicious, it is blocked.

    • If GTI file reputation is clean, it is allowed.

    • If dynamic analysis reports an executable or data file as malicious, it is blocked.

    • Auto-classified blocked and allowed executables are added to the Allowed and Blocked Hashes tabs in File Hashes page.

    Note

    Make sure that GTI is reachable. This can be done by configuring the local DNS Server (or proxy) by selecting Devices → <Admin Domain Name> → Global → Default Device Settings → Common → Name Resolution. Enter the IP Address (IPv4 or IPv6) here.

  • Manual Classification: You can also manually classify the executables from the Manager. Based on their overall malware confidence and their network behavior, you can classify them as allowed or blocked.

    Note

    Manual classification has the highest priority and takes precedence over auto-classification.

The following aspects are used to classify executables:

Executable classification

Manually allowed

Manually blocked

Digitally trusted

Dynamic analysis

Auto-GTI allowed

Auto-GTI blocked

Gets classified as

Yes

-

Yes or No

Any

Yes or No

Yes or No

Allowed

-

Yes

Yes or No

Any

Yes or No

Yes or No

Blocked

Not classified

Yes

Any

Yes or No

Yes or No

Allowed

Not classified

No

Malicious

Yes or No

Yes or No

Blocked

Not classified

No

Not malicious

Yes

No

Allowed

Not classified

No

Not malicious

No

Yes

Blocked

Scenario: A new executable is seen in your network

-

Yes

Any

Unknown

Allowed

-

No

Malicious

Unknown

Blocked

-

No

Not malicious

Unknown

Unclassified



Note

A new executable is not known to Trellix GTI and an administrator cannot classify it until its behavior is analyzed. For the second occurrence, GTI discovers and computes reputation for an unclassified executable, and the NTBA classification may vary accordingly.