• Last Updated
    Apr 1, 2025
  • Version
    1.4.1
  • Compatibility
    ThreatQ versions >= 5.12.0
  • Trellix (McAfee) TIE Connector

    Overview

    Trellix is the device-to-cloud cybersecurity company. Inspired by the power of working together, Trellix creates business and consumer solutions that make our world a safer place for the benefit of all. Our holistic, automated open security platform allows all your disparate products to co-exist, communicate, and share threat intelligence with each other anywhere in the digital landscape. Where machine automation is converged with human intelligence so you can streamline workflows more efficiently. Where your team is freed from unnecessary operational burden and is empowered to strategically fight adversaries. Where you can orchestrate all things security through a single management system. Where all your security products adapt to new threats skillfully and work synergistically to increase protection, and speed up detection and correction—across the entire threat defense lifecycle.

     

    This connector will interact with the Trellix TIE server. The TIE server is a database of malicious files and their reputations. The integration will pull the indicator hashes from the ThreatQ Threat Library; perform a potentially custom mapping of indicator attributes to the Trellix file reputations, and push these indicators to the TIE server.

     

    • User configurable rate limiting: ThreatQ will not push more than the configured indicators per day in the TIE server. 1000 indicators per day is the hard limit. The rate limit is honored regardless of how often the connector runs.
    • ThreatQ indicator scores are mapped to Trellix reputation scores via user configuration.
    • A user can export only indicators of interest out of the ThreatQ platform via configuration.
    • Ability to use Trellix EPO's provisioning capability to get a signed certificate for communication with the TIE server.
    • Ability to enrich any hash indicators in TQ sent to Trellix TIE with any additional information from the Trellix ecosystem.
    • New in Version 1.2.0: Ability to enrich any hash indicators in ThreatQ sent to Trellix TIE with any additional information from the Trellix ecosystem.

     

    Copyright © 2025, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy