The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Embedded URL analysis

Prev Next

The embedded URL analysis feature allows the Network Security appliance to extract suspicious URLs that are embedded in a PDF file or a Microsoft Office file within an email message body. When the Network Security appliance extracts a suspicious URL from the PDF file or the Microsoft Office file in an email message, it sends the URL to the URL analysis service for analysis. When guest images updates are downloaded and installed on the Network Security appliance, they are used to extract the suspicious URLs from a Microsoft Office file in an email message during dynamic analysis. Before the Network Security appliance submits the PDF file or the Microsoft Office file for analysis, a verdict is determined for the embedded URL based on custom allowed and blocked lists, Advanced URL Defense, typo squatting, and so forth.

Note

Before the Network Security appliance submits a Microsoft Office file for analysis, a verdict cannot be determined for the embedded URL based on URL Dynamic Analysis (DUA).

If the embedded URL that is extracted from the PDF file or the Microsoft Office file are detected as malicious, the Network Security appliance immediately blocks the email from being delivered to you and marks the malicious email for quarantine.

Note

The embedded URL analysis feature is enabled by default.

Usage guidelines

Trellix recommends that you follow these usage guidelines when you are managing embedded URL analysis: