TrellixThreat Intelligence

    Threat Intelligence Exchange

    A reputation broker that turns your whole stack into one immune system.

    A threat seen once on one endpoint should never be unknown to the rest of your defences. Trellix Threat Intelligence Exchange (TIE) acts as a reputation broker: it blends global threat data with local intelligence from your endpoints, gateways, and analysis tools, then shares that collective verdict across your security ecosystem in real time over the Data Exchange Layer. Faltrox operates it so the whole stack learns from every encounter.

    Overview

    What Threat Intelligence Exchange is

    Trellix Threat Intelligence Exchange (TIE) acts as a reputation broker that turns your whole security stack into one immune system. A threat seen once on one endpoint should never be unknown to the rest of your defences — but the lag between one part of your defence encountering a threat and the rest of it knowing is where advanced attacks live. TIE closes that gap from days or weeks down to milliseconds.

    It blends global threat data with local intelligence from your endpoints, gateways, and analysis tools, then shares that collective verdict across your ecosystem in real time over the open Data Exchange Layer. Administrators can tune and override the intelligence to their environment, and unknown files escalate automatically to sandboxing. Faltrox operates it so the whole stack learns from every encounter.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Endpoints & Gateways

    Shares reputation across endpoint, gateway, and advanced-analysis solutions in real time.

    02

    Network & Data Centre

    Extends collective intelligence from the endpoint to the network edge and data centre.

    03

    Unknown Files

    Makes an informed trust decision on never-before-seen files using local and global context.

    04

    The Whole Ecosystem

    An open framework lets every security solution dynamically join and act on shared intelligence.

    05

    Local + Global Intel

    Combines Trellix Global Threat Intelligence with locally gathered reputation for accuracy.

    06

    Targeted Attacks

    Local surveillance captures the unique, laser-focused assaults a global feed alone would miss.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Encounter

      When an unidentified file is seen anywhere on the network, TIE is contacted to determine whether a reputation exists.

    2. 02

      Broker

      It blends endpoint context — file, process, and environmental attributes — with organisational prevalence and global intelligence.

    3. 03

      Decide

      A context-aware trust level is assigned: a prevalent internal app is allowed, a suspiciously packed unknown is blocked or sandboxed.

    4. 04

      Share

      The verdict propagates instantly across every integrated solution over the Data Exchange Layer.

    5. 05

      Immunise

      The reputation is stored, so if the file is seen again anywhere it is immediately detected rather than re-evaluated.

    Capabilities

    Key capabilities

    Reputation Broker

    Combines local intelligence from across your organisation with external global threat data, instantly sharing the collective verdict so every solution can act on shared intelligence.

    Data Exchange Layer (DXL)

    An open framework that lets endpoint, gateway, network, and data-centre solutions dynamically join the ecosystem — replacing many brittle point-to-point API integrations with one shared bus.

    Adaptive Immunisation

    When an unknown file is convicted anywhere on the network, the updated reputation propagates to every system in real time — so the same threat is immediately detected the next time it appears.

    Context-Aware Decisions

    Blends file, process, and environmental attributes with organisational prevalence and age, so a custom internal app with high prevalence is allowed while a suspiciously packed unknown gets a low trust level.

    Local Tuning & Override

    Administrators assemble, override, augment, and tune the intelligence to their environment, so protection reflects the organisation’s own context rather than a generic global feed alone.

    Sandbox Escalation

    When more information is needed, files route automatically to Trellix Intelligent Sandbox for deeper analysis, with the resulting verdict shared back across the ecosystem via DXL.

    Endpoint Enforcement

    Trellix Endpoint Security acts on the combined local and global reputation, with Real Protect and Dynamic Application Containment protecting patient zero while further analysis runs.

    SIEM Investigation

    Trellix Enterprise Security Manager lets you dig into IOCs identified by TIE, with historical data and automated watch lists to increase investigation efficiency.

    Specifications

    Technical detail

    Role
    Reputation broker across the security ecosystem
    Transport
    Trellix Data Exchange Layer (DXL) — open framework
    Intelligence Sources
    Trellix GTI (global) blended with local endpoint, gateway, and analysis intelligence
    Reputation Types
    File, process, and environmental attributes; organisational prevalence and age
    Integrations
    Endpoint Security, Intelligent Sandbox, Enterprise Security Manager

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Threat Intelligence Exchange for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What problem does TIE actually solve?

    The lag between one part of your defence encountering a threat and the rest of it knowing. TIE closes the gap from encounter to containment for advanced targeted attacks from days, weeks, or months down to milliseconds, by sharing a convicted reputation across every integrated solution instantly.

    02How does it decide on a file it has never seen?

    It blends endpoint context — file, process, and environmental attributes — with organisational prevalence, age, and collective threat intelligence. A widely used internal app with no global reputation is allowed; a never-before-seen, suspiciously packed file gets a low trust level and may be blocked or sent for sandboxing.

    03What is the Data Exchange Layer?

    DXL is the open messaging framework TIE uses to share intelligence. Instead of building and maintaining direct API integrations between every pair of security tools, solutions join one shared bus — which is what reduces implementation and operational cost while keeping everything in sync in real time.

    04Can we tune it to our environment?

    Yes. Administrators can assemble, override, augment, and tune the intelligence, so a locally convicted or locally trusted file behaves the way your organisation needs. That local prioritisation is stored and applied instantly to future encounters.

    05Does it work with third-party tools or only Trellix?

    DXL is designed as an open framework so all security solutions can dynamically join the ecosystem. In practice it delivers the most value stitching the Trellix portfolio together, which is how Faltrox typically deploys it.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us