You configure the anti-malware options in an Advanced Malware policy and then assign it to the required Sensor monitoring resources, such as ports, interfaces, and subinterfaces. You must do a configuration and signature set update for any changes in the policy to take effect.
Task
Update the scanning options of the Advanced Malware policy

Note: Name resolution must be enabled on devices which will be using the GTI File Reputation malware engine.
File scanning options
Field name | Description |
|---|---|
File Type | The file types to be scanned. For information about the supported file types, refer to the table Advanced malware file extension support below. |
Maximum File Size (KB) Scanned | The maximum size currently supported for the corresponding file type. Files that exceed the specified size are not analyzed for malware by any of the engines, including the block and allow lists. The default values are displayed in the Default Malware Policy as well as when you create a policy. The default values are the optimum sizes recommended by Trellix Labs based on their research on malware. You can set the maximum file size value up to (25*1024) KB/25 MB for all file types. However, the Trellix IPS Anlysis engine and Trellix Cloud engine have a file-size limit. The limits for each Sensor model are as follows:
Note: Trellix recommends that for any file type, you do not set a value more than (5*1024) KB/5 MB as the maximum file size as this might affect the Sensor's performance. |
Malware Engines | The Malware engines to scan the selected file type. If you select Gateway Anti-Malware for a File Type, you must either use an NS-series Sensor running on Sensor software version 9.1 or above, or NTBA. For MVX to work, you must integrate the corresponding Sensors with the VX appliance. See the chapter Integration with MVX for more information. For Trellix Intelligent Sandbox to work, you must integrate the corresponding Sensors with Trellix Intelligent Sandbox. See the chapter Integration with Trellix Intelligent Sandbox for more information. |
Action Thresholds | Specifies the type of response to be made for the attack. The types of responses are:
|
Advanced malware file extension support

