The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring retroactive detection from AV-Suite

Prev Next

You can configure the settings for retroactive detection from AV-Suite by using the File Protect appliance CLI:

  • Configuring AV-Suite to store objects using the CLIConfiguring AV-Suite to store objects using the CLI

  • Configuring retroactive detection updates from AV-Suite using the CLIConfiguring retroactive detection updates from AV-Suite using the CLI

You can configure how often the File Protect appliance queries the AV-Suite server for previous retroactive verdicts. You can also configure how long you want to store information (filename, file type, engine type, MD5 checksum, and SHA-256 hash file) in AV-Suite for the malicious and nonmalicious objects and to check for a particular object to update. The verdict remains in AV-Suite but other information about the object is removed.

Prerequisites

  • Administrator or Operator access to the File Protect appliance

  • A two-way sharing CONTENT_UPDATES license

  • Verify that AV-Suite integration is enabled. Verify that AV-suite version 6 is configured. Use the show static-analysis config command.

  • Enable retroactive detection from AV-Suite. Use the analysis retro-hunt enable command.