The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Analyze Malware Files

Prev Next

You can leverage the analysis technique provided by Trellix IPS to perform an in-depth analysis of the malware detected in your network. The Manager provides you with a complete view of the malware and threats on your network for further analysis and actions, thus providing a comprehensive view of the threat landscape in your network. You can view the Top Malware Files. This dashboard is populated because a malicious file has been detected. In addition to viewing the threats to your network, the Manager also provides you the option to archive malware files.

To view malware detected by Trellix IPS, use the Top Malware Files monitor. The dashboard displays the Malware File Hash and the Attack Count of the detected malware. Security monitors are displayed as bar charts in the Dashboard page.

Top Malware Files

Top Malware Files



If you want to drill down further on a specific malware, click on a bar, and you will be redirected to the Analysis → Malware Files page, which displays additional details on that malware. This page provides you with the flexibility of filtering and sorting the information displayed based on your choice. In addition to these filtering/sorting options, you can also view the alerts that match the filter criteria by opening the Attack Log page directly from the Threat Explorer. You can view the malware files specific to admin domains by selecting the required admin domain from the Domain drop-down list. Summarized data for malware files, which includes data from the child domains, also can be viewed. If you have integrated the Manager with ePolicy Orchestrator - On-premises or Logon Collector, you can view the host type, host name, user name, operating system details, top10 anti-virus events, and the details of system security products installed on the host.

The following chart gives you the comprehensive analysis options provided by the Malware Files page. These tabs are explained in the subsequent sections.

Malware analysis

Malware analysis



The following filter options are provided.

View data specific to admin domain

View data specific to admin domain



Analyze detected malware within a specific time

Analyze detected malware within a specific time



Analyze the type of malware, whether blocked, unblocked, or all

Analyze the type of malware, whether blocked, unblocked, or all



Analyze the malware based on malware confidence returned by engines

Analyze the malware based on malware confidence returned by engines



Details of the detected malware

Details of the detected malware



Option

Definitions

Hash

Displays the hash value of the file and the actions that you can take.

  • Actions— Click Take action to take the following actions:

    • Export— Click to download the malware file from the Manager server to a network location. The file is saved with an extension .trellix. This prevents you from even accidentally opening the malicious file. The file is available for download only if you enable the Save File option for the corresponding file type in the Advanced Malware policy that detected this malware.

      Note

      The antivirus program on your computer might prevent you from downloading the file.

    • Allow— Click to automatically add the file to the Manager's allow list. In the next 5 minutes, the Manager sends the MD5 hash value to the allow list of all the Sensors.

      Note

      In case MD5 entries limit has reached, the Manager adds SHA256 hash value(s) of the malware file(s) to its allow list and sends the same hash value(s) to the Sensor through incremental or full update.

    • Block— Click to automatically add the file to the Manager's block list. In the next 5 minutes, the Manager sends the MD5 hash value to the block list of all the Sensors.

      Note

      In case MD5 entries limit has reached, the Manager adds SHA256 hash value(s) of the malware file(s) to its block list and sends the same hash value(s) to the Sensor through incremental or full update.

  • MD5 — Displays the MD5 hash of the file

  • SHA1 — Displays the SHA1 hash of the file

  • SHA256 — Displays the SHA256 hash of the file

Overall Malware Confidence

The overall malware confidence level returned by the configured malware scanning engines

Individual Engine Confidence

The confidence level returned by each configured malware scanning engine, individually. Click GUID-5974C0ED-5F86-483F-B79B-C3ED90C1FE61-low.png to view the engine-specific details.

Last Attack

The date and time the last malware was detected.

Total Attacks

The number of times the malware was detected.

Last File Name

The name of the last saved malware file. In case of HTTP downloads it will be the URL.

File Size (bytes)

The size of the malware file saved

Comment

Additional comments on the detected malware

Attack Log

Upon double-clicking on the malware file hash, the Attack Log opens where you can view and analyze alerts related to the selected hash.

Attack log alerts for the hash selected

Attack log alerts for the hash selected



To close the attack log, click Back or GUID-DC163F46-CD0C-4C3C-A567-E2D623D22ABD-low.png icon.

Manage allow and block lists

The Manage allow and block lists is a link to the File Hashes page. See Manage allow and block lists for more information.