The Manager provides options to auto-classify or manually classify the executables. Executables that appear as unclassified can be allowed or blocked. The Manager pushes the updates in the allowed and blocked hashes to the NTBA Appliance every five minutes.
The executables are classified as the following:
Allowed: Executables that are considered safe
Blocked: Executables that are not considered safe or not allowed per corporate policy
Unclassified: Executables that are yet to be classified
You can classify executables from any of the following:
Endpoint Baseline Generator: When the Endpoint Baseline Generator tool is run on a computer, it scans the computer, calculates the heuristics for all the executable hashes on the system, and generates an XML file. This XML file contains information, such as file name, file size, hash type (MD5), and file hash.
Trellix recommends that you run the tool on a system that can be treated as a baseline computer profile for your organization. You can then use the import option in the Manager to append your list to the existing allow and block list in the Manager.
Auto-Classification: You can configure Auto-Classification Settings at the Global level of the EIA Integration page to classify executables based on the following:
If the executable is signed and trusted, it is allowed.
If GTI file reputation is malicious, it is blocked.
If GTI file reputation is clean, it is allowed.
If dynamic analysis reports an executable or data file as malicious, it is blocked.
Auto-classified blocked and allowed executables are added to the Allowed and Blocked Hashes tabs in File Hashes page.
Note
Make sure that GTI is reachable. This can be done by configuring the local DNS Server (or proxy) by selecting → → → → → . Enter the IP Address (IPv4 or IPv6) here.
Manual Classification: You can also manually classify the executables from the Manager. Based on their overall malware confidence and their network behavior, you can classify them as allowed or blocked.
Note
Manual classification has the highest priority and takes precedence over auto-classification.
The following aspects are used to classify executables:
Manually allowed | Manually blocked | Digitally trusted | Dynamic analysis | Auto-GTI allowed | Auto-GTI blocked | Gets classified as | |
|---|---|---|---|---|---|---|---|
Yes | - | Yes or No | Any | Yes or No | Yes or No | Allowed | |
- | Yes | Yes or No | Any | Yes or No | Yes or No | Blocked | |
Not classified | Yes | Any | Yes or No | Yes or No | Allowed | ||
Not classified | No | Malicious | Yes or No | Yes or No | Blocked | ||
Not classified | No | Not malicious | Yes | No | Allowed | ||
Not classified | No | Not malicious | No | Yes | Blocked | ||
Scenario: A new executable is seen in your network | |||||||
- | Yes | Any | Unknown | Allowed | |||
- | No | Malicious | Unknown | Blocked | |||
- | No | Not malicious | Unknown | Unclassified | |||
Note
A new executable is not known to Trellix GTI and an administrator cannot classify it until its behavior is analyzed. For the second occurrence, GTI discovers and computes reputation for an unclassified executable, and the NTBA classification may vary accordingly.