The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add file hash to Allow/Block list

Prev Next

The MD5 hash value of a malware file added to the allow list is exempted from analysis as it is safe. On the other hand, the MD5 hash value of a malware file added to the block list is immediately blocked as it is malicious. You can add the file hash of a malware alert from the Attack Log.

Note

In case MD5 entries limit has reached, the Manager adds SHA256 hash value(s) of the malware file(s) to its allow/block list and sends the same hash value(s) to the Sensor through incremental or full update.

There are multiple ways a file hash can be added to the Allow/Block list.

Adding a hash from the <Attack Name> panel:

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.

  2. Double-click the malware alert whose file hash you want to allow or block.

    The <Attack Name> panel opens on the right hand side of the browser window.

  3. Click the Details tab.

  4. The file hashes are listed within the File Hash section under the File Name field. Click Allow or Block to add the hash to Allow or Block list.

Adding a hash from Other Actions menu:

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.

  2. Select the malware alert whose file hash you want to allow or block.

  3. Click Other Actions, select Create Exception, and click Allow File Hash: <hash file>/Block File Hash: <hash file>.

  4. Click Yes.

    A successfully allowed/blocked message is displayed.

    You can view/edit the allowed/blocked file hashes under Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → File Hashes.

Adding a hash from Malware Files page:

  1. Navigate to Analysis → <Admin Domain Name> → Malware Files.

  2. Click Take action for a specific entry and select Allow or Block to automatically add the file to the Manager's allow/block list. In the next 5 minutes, the Manager sends the hash value to the allow/block list of all the Sensors, depending on the action taken.

Enabling "Add to Block List" through the Advanced Malware Policy Page:

  1. Navigate to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware.

    The Advanced Malware policies are listed.

  2. Double click a policy to edit.

  3. In the policy configuration page, for a specific File Type, choose the severity under Add to Block List column and click Save.

    For a file to be added to the block list, the file's severity must be the same or more than the severity you specify. For example, if you specify high as the criteria, then files of severity high and very high are added to the block list. Within the next 5 minutes, the Manager adds this file to the local block list of all the Sensors that it manages.