The MD5 hash value of a malware file added to the allow list is exempted from analysis as it is safe. On the other hand, the MD5 hash value of a malware file added to the block list is immediately blocked as it is malicious. You can add the file hash of a malware alert from the Attack Log.
Task
- Navigate to Analysis → <Admin Domain Name> → Attack Log.
- Select the malware whose file hash you want to allow or block.
-
Click
Other Actions, select
Create Exception, and click
Allow File Hash: <hash file>/Block File Hash: <hash file>.
A confirmation message is displayed.
-
Click
Yes.
A successfully allowed/blocked message is displayed.
You can view/edit the allowed/blocked file hashes under Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → File Hashes.
For more information on allowing/blocking file hashes, see the Trellix Intrusion Prevention System Product Guide.