The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add hash values to the block list

Prev Next

You can add MD5 or SHA256 hash values of files that you want to be treated as malicious when found in HTTP and SMTP downloads. If a file's hash matches a hash value in the block list, the Sensor treats the file as malicious of very high severity.

  1. Select Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → File Hashes.

    On the Blocked Hashes tab, you can add the hash values to be blocked, manage the file types to be checked for the blocked hashes, and view the maximum file size scanned.

    Blocked hashes
    Blocked hashes


    The following table describes the details displayed on the Blocked Hashes tab.

    Format

    Description

    File Hash

    Specifies the file hash. The File Hash should be in MD5 or SHA256 format

    File Name

    Specifies the name of the file along with the file extension

    Hash Type

    Specifies the format of the hash. The supported file hash types are MD5 and SHA256.

    Last Updated

    Displays the following:

    • Time: Specifies the time stamp of the imported block list file hash

    • By: Specifies the user who imported the block list file hash

    Comment

    Any comments about the list

  2. File hashes can be added through this page in two ways — using the Import option or the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon. To import a file containing the hash values, click Other Actions → Import.

    GUID-5278DA61-C330-4FF2-8E66-4AF8C516F309-low.png
  3. Import from CSV window appears. Use the Append option to add a new list of hashes or to append a list of hashes to an existing list. Use the Replace option to remove the existing list of hashes and add a new list from the file being imported.

    The file to be imported should be in the following CSV format.

    <Name of the file with extension (like .exe, .com)>,<File size>,<Hash type>,<File hash>,<Description>

    Example file format for MD5 hashes: Application.exe, 1024000, MD5, 30a4edd18db6dd6aaa20e3da93c5f425, textual description.

    Example file format for SHA256 hashes: Service.exe, 1024000, SHA256, a6279afa088a2e200b3b222c3169e9dce332a08759512800b48bf038e47bf528, textual description. Also note that if you are adding multiple entries in the CSV file, each entry has to be in a new line.

    The following is a sample for a CSV file with multiple file hashes.

    GUID-581CE23A-8E3E-49B9-8EF4-B0DA69239E01-low.png

    The following table describes the details of the files to be imported in the CSV or XML format.

    Format

    Description

    <Name of the file with extension (like .exe, .com)>

    Specifies the name of the file to be imported, along with the file extension. This is an optional value.

    <File size>

    Specifies the size of the file to be imported. The file size should be a valid integer.

    Note

    File size value is mandatory. It is used by the Sensor as a secondary matching criterion when the same hash has been added to both the block list and allow list.

    Note

    If the file size is unknown, you can add a placeholder value like 1 to the CSV file as this value is mandatory.

    <Hash type>

    Specifies the format of the hash. The supported file hash types are MD5 and SHA256.

    <File hash>

    Specifies the hash for the file to be imported

    <Description>

    Specifies the description of the file to be imported. This is an optional value.

    Note

    If you import the same file hashes to allow list first and then to block list, the hashes in the allow list will be removed and added to the block list. Similarly, if you import the same file hashes to block list first and then to allow list, the hashes in the block list will be removed and added to the allow list.

  4. Click Browse to locate the CSV file that contains the list of hashes you want to import.

    GUID-54CDCB12-A9BC-4ED5-946C-0E83244A3912-low.png
  5. Click Import upon selecting the CSV file.

  6. To add a single file hash to the blocked hashes, click GUID-0208387A-BF4A-410F-9CFB-52AE08321E35-low.png.

    Click Save after entering the values in File Hash, File Name, and Comment. The Comment field is optional.

    Note

    The File Hash should be a 32 or 64 digit hexadecimal value depending on the hash type.

    Add a single block list file hash value
    Add a single block list file hash value


    Note

    • The Manager running on 11.1 Update 1 or later releases supports addition of up to 400,000 hash entries (allowed and blocked combined) with a limit of 200,000 per each hash type. Manager prior to 11.1 Update 1 release supports addition of only MD5 hashes up to 100,000 entries (allowed and blocked combined).

    • Sensors prior to 11.1 Update 1 release do not support SHA256 hashes. The maximum number of hashes supported (cumulative of Blocked Hashes and Allowed hashes) by these Sensors is 100,000.

    • Sensors running on 11.1 Update 1 or later releases support both SHA256 and MD5 hashes. NS-series Sensors support a maximum of 200,000 hashes for each hash type while the Virtual IPS Sensors support a maximum of 100,000 hashes for each hash type. If the Manager has both NS-series and virtual Sensors, entries over 100,000 in each hash type are pushed only to the NS-series Sensors. The push fails on virtual Sensors and a fault is raised which can be noticed in the Faults (Manager → Troubleshooting → Logs → Faults) tab.

    • In case of heterogeneous environments, if the total MD5 hash entries exceed 100,000:

      • A limit exceed error can be seen in filetransfer.log during a bulk (full) update

      • A fault will be raised in the Faults tab and error count will be incremented at the Sensor level during an incremental update. Refer to show ab stats command for more information.

        Note

        A Full update is triggered when the total entries are more than 4000; else, an incremental update is triggered to all the Sensors connected to the Manager.

    • In case MD5 and SHA256 hashes of the same file are added, the MD5 hash takes precedence over SHA256 hash of the file during analysis.

  7. To export the blocked hashes from the Manager to a local system, click Other Actions → Export All.

  8. To delete specific entries from the block list, select them by holding the Shift or Ctrl key and clicking on the required rows. Then click GUID-3F088FC3-D445-44E2-83DE-8BF15559A099-low.png.

    The deleted hashes are now neither in the allow list nor in the block list.

  9. To remove all the entries, select Other Actions → Delete All.

  10. To move specific entries to the allow list, select the entries and then select Other Actions → Move to Allow List.

    • A manual signature set push is not required each time the allow list or the block list is updated. The Manager updates the Sensor dynamically with the modified entries in the allow list or block list, at an interval of 5 minutes. These updates occur in bulk (the complete list of entries) or increments (added/deleted entries). To view the status of these updates, issue the show ab statscommand. For more information, see the CLI commands section in the Trellix Intrusion Prevention System Product Guide.