Threat Intelligence Exchange
A reputation broker that turns your whole stack into one immune system.
A threat seen once on one endpoint should never be unknown to the rest of your defences. Trellix Threat Intelligence Exchange (TIE) acts as a reputation broker: it blends global threat data with local intelligence from your endpoints, gateways, and analysis tools, then shares that collective verdict across your security ecosystem in real time over the Data Exchange Layer. Faltrox operates it so the whole stack learns from every encounter.
Overview
What Threat Intelligence Exchange is
Trellix Threat Intelligence Exchange (TIE) acts as a reputation broker that turns your whole security stack into one immune system. A threat seen once on one endpoint should never be unknown to the rest of your defences — but the lag between one part of your defence encountering a threat and the rest of it knowing is where advanced attacks live. TIE closes that gap from days or weeks down to milliseconds.
It blends global threat data with local intelligence from your endpoints, gateways, and analysis tools, then shares that collective verdict across your ecosystem in real time over the open Data Exchange Layer. Administrators can tune and override the intelligence to their environment, and unknown files escalate automatically to sandboxing. Faltrox operates it so the whole stack learns from every encounter.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Endpoints & Gateways
Shares reputation across endpoint, gateway, and advanced-analysis solutions in real time.
Network & Data Centre
Extends collective intelligence from the endpoint to the network edge and data centre.
Unknown Files
Makes an informed trust decision on never-before-seen files using local and global context.
The Whole Ecosystem
An open framework lets every security solution dynamically join and act on shared intelligence.
Local + Global Intel
Combines Trellix Global Threat Intelligence with locally gathered reputation for accuracy.
Targeted Attacks
Local surveillance captures the unique, laser-focused assaults a global feed alone would miss.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Encounter
When an unidentified file is seen anywhere on the network, TIE is contacted to determine whether a reputation exists.
- 02
Broker
It blends endpoint context — file, process, and environmental attributes — with organisational prevalence and global intelligence.
- 03
Decide
A context-aware trust level is assigned: a prevalent internal app is allowed, a suspiciously packed unknown is blocked or sandboxed.
- 04
Share
The verdict propagates instantly across every integrated solution over the Data Exchange Layer.
- 05
Immunise
The reputation is stored, so if the file is seen again anywhere it is immediately detected rather than re-evaluated.
Capabilities
Key capabilities
Reputation Broker
Combines local intelligence from across your organisation with external global threat data, instantly sharing the collective verdict so every solution can act on shared intelligence.
Data Exchange Layer (DXL)
An open framework that lets endpoint, gateway, network, and data-centre solutions dynamically join the ecosystem — replacing many brittle point-to-point API integrations with one shared bus.
Adaptive Immunisation
When an unknown file is convicted anywhere on the network, the updated reputation propagates to every system in real time — so the same threat is immediately detected the next time it appears.
Context-Aware Decisions
Blends file, process, and environmental attributes with organisational prevalence and age, so a custom internal app with high prevalence is allowed while a suspiciously packed unknown gets a low trust level.
Local Tuning & Override
Administrators assemble, override, augment, and tune the intelligence to their environment, so protection reflects the organisation’s own context rather than a generic global feed alone.
Sandbox Escalation
When more information is needed, files route automatically to Trellix Intelligent Sandbox for deeper analysis, with the resulting verdict shared back across the ecosystem via DXL.
Endpoint Enforcement
Trellix Endpoint Security acts on the combined local and global reputation, with Real Protect and Dynamic Application Containment protecting patient zero while further analysis runs.
SIEM Investigation
Trellix Enterprise Security Manager lets you dig into IOCs identified by TIE, with historical data and automated watch lists to increase investigation efficiency.
Specifications
Technical detail
- Role
- Reputation broker across the security ecosystem
- Transport
- Trellix Data Exchange Layer (DXL) — open framework
- Intelligence Sources
- Trellix GTI (global) blended with local endpoint, gateway, and analysis intelligence
- Reputation Types
- File, process, and environmental attributes; organisational prevalence and age
- Integrations
- Endpoint Security, Intelligent Sandbox, Enterprise Security Manager
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Threat Intelligence Exchange for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What problem does TIE actually solve?
The lag between one part of your defence encountering a threat and the rest of it knowing. TIE closes the gap from encounter to containment for advanced targeted attacks from days, weeks, or months down to milliseconds, by sharing a convicted reputation across every integrated solution instantly.
02How does it decide on a file it has never seen?
It blends endpoint context — file, process, and environmental attributes — with organisational prevalence, age, and collective threat intelligence. A widely used internal app with no global reputation is allowed; a never-before-seen, suspiciously packed file gets a low trust level and may be blocked or sent for sandboxing.
03What is the Data Exchange Layer?
DXL is the open messaging framework TIE uses to share intelligence. Instead of building and maintaining direct API integrations between every pair of security tools, solutions join one shared bus — which is what reduces implementation and operational cost while keeping everything in sync in real time.
04Can we tune it to our environment?
Yes. Administrators can assemble, override, augment, and tune the intelligence, so a locally convicted or locally trusted file behaves the way your organisation needs. That local prioritisation is stored and applied instantly to future encounters.
05Does it work with third-party tools or only Trellix?
DXL is designed as an open framework so all security solutions can dynamically join the ecosystem. In practice it delivers the most value stitching the Trellix portfolio together, which is how Faltrox typically deploys it.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us