The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling controlled live mode

Prev Next

You can enable or disable the controlled live mode by using the appliance Web UI or CLI:

Controlled live mode enables the ADD Product Series appliance to detect malware that requires remote objects. Controlled live mode monitors and manages communication between remote hosts and the suspicious binary under analysis. MVX sends and receives this traffic on the live ether1 or ether2 interface.

Important

Controlled live mode is disabled by default. You enable the feature separately from configuring the feature settings.

For more information, see Configuring controlled live mode on .