The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add Advanced Malware Policy

Prev Next

This URL adds a new advanced malware policy.

Resource URL

POST /malwarepolicy

Request Parameters

Payload Request Parameters:

Field Name Description Data Type Mandatory
properties Basic properties of the malware policy Object Yes
scanningOptions List of scanning options per file type Array No

Details of properties:

Field Name Description Data Type Mandatory
policyName Policy name String Yes
description Description String No
domainId Domain id Number Yes
visibleToChild Is the policy visible to child Boolean Yes
protocolsToScan List of protocols supported Array No

Details of object in protocolsToScan:

Field Name Description Data Type Mandatory
protocolName Protocol name String Yes
protocolNumber Protocol number Number Yes
enabled Protocol status Boolean Yes

Details of object in scanningOptions:

Field Name Description Data Type Mandatory
fileType Type of the file String Yes
malwareEngines List of malware engines supported Array Yes
actionThresholds Action threshold details Object Yes
maximumFileSizeScannedInKB Maximum file size scanned in KB Number Yes

Details of object in malwareEngines:

Field Name Description Data Type Mandatory
name Malware engine name String Yes
status Status can be DISABLED/UNCHECKED/CHECKED String Yes
id Malware engine id Number Yes

Details of actionThresholds:

Field Name Description Data Type Mandatory
alert Alert to be sent, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes
block Blocking settings, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes
sendTcpReset Send TCP reset, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes
saveFile Save file can be "DISABLED" / "ALWAYS" /"VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes
addToBlockList Add to block list can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
createdResourceId Unique id of the created malware policy Number

Example

Request

POST https://%3CNSM_IP%3E/sdkapi/malwarepolicy

 {
       "properties":
       {
           "policyName": "Test",
           "description": "Add Malware Policy",
           "domainId": 0,
           "visibleToChild": true,
           "protocolsToScan":
           [
               {
                   "protocolName": "HTTP",
                   "protocolNumber": 16,
                   "enabled": true
               },
               {
                   "protocolName": "SMTP",
                   "protocolNumber": 12,
                   "enabled": true
               }
           ]
       },
       "scanningOptions":
       [
           {
               "fileType": "Executables",
               "maximumFileSizeScannedInKB": 5120,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": " Blocklist and Allowlist",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "CHECKED"
                   },
                   {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                             }
               ],
               "actionThresholds":
               {
                   "alert": "LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
                   "addToBlockList": "DISABLED"
               }
           },
           {
               "fileType": "MS Office Files",
               "maximumFileSizeScannedInKB": 1024,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "DISABLED"
                   },
                   {
                       "name": "Blocklist and Allowlist ",
                       "id": 2,
                       "status": "CHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "CHECKED"
                   },
                   {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "MEDIUM",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
                   "addToBlockList": "DISABLED"
               }
           },
           {
               "fileType": "PDF Files",
	     "maximumFileSizeScannedInKB": 1024,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": " Blocklist and Allowlist ",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "CHECKED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "CHECKED"
                   },
  	        {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
	         "addToBlockList": "DISABLED"
               }
           },
           {
               "fileType": "Compressed Files",
	     "maximumFileSizeScannedInKB": 5120,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "DISABLED"
                   },
                   {
                       "name": " Blocklist and Allowlist ",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "UNCHECKED"
                   },
	        {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
	         "addToBlockList": "DISABLED"
               }
           },
	{
               "fileType": "Android Application Package",
	     "maximumFileSizeScannedInKB": 2048,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "CHECKED"
                   },
                   {
                       "name": " Blocklist and Allowlist ",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "DISABLED"
                   },
  	        {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
	         "addToBlockList": "DISABLED"
               }
           },
           {
               "fileType": "Java Archive",
	     "maximumFileSizeScannedInKB": 2048,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "DISABLED"
                   },
                   {
                       "name": " Blocklist and Allowlist ",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "UNCHECKED"
                   },
	        {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
	         "addToBlockList": "DISABLED"
               }
           }
 
       ]
    } 

Response

 {
       "createdResourceId": 301
    } 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 1105 Invalid domain
2 400 2508 Malware policy name is required
3 400 2509 Invalid protocol list
4 400 2513 Name must contain only letters, numerical, spaces, commas, periods, hyphens or underscore
5 400 2514 Name already in use
6 400 2516 Length of name field cannot exceed 40 characters
7 400 2517 Length of description field cannot exceed 149 characters