The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable mobile malware detection

Prev Next

Following are the steps to enable mobile malware detection:

  1. The GTP feature is disabled on the Sensor by default. You can enable the GTP feature on the Sensor by using the these steps:

    • Go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → Advanced Device Settings and select Inspect Tunneled Traffic and click Save. This enables parsing of traffic for all supported tunneling protocols including GTP for malware detection. By default, this checkbox is deselected.

      Note

      At an admin domain level, configure this for multiple Sensors by navigating to Devices → <Admin Domain Name> → Global → IPS Device Settings → Advanced Device Settings and select Inspect Tunneled Traffic and click Save.

    • Check the status of tunneled traffic with this CLI command:

      Syntax:

      show parsetunneledtraffic status

      Displays the status of the current tunneling configuration of the Sensor.

  2. Enable GTI File Reputation under Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware and click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png.

    • To create a new policy and enable the GTI File Reputation for the required file type, navigate to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Manager.

  3. Configure the DNS Server under Devices → <Admin Domain Name> → Global → Common Device Settings → Name Resolution.

    For more information, see section Configure the DNS server details, chapter Configure Firewall Policies.

  4. Set the policy to Default Prevention under Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS.

    Note

    The Default Prevention policy is set by default. In case it is not set, then navigate to the above mentioned path to set it.

  5. You can set and view the following policy details configured in the Manager:

    • Reconnaissance attack details

    • Callback Detector details

    • Network Forensics details

    • Packet Capture details

    • Customizing scan attack details

    Trellix IPS generates alerts and events, which help keep track of the malware, bots, worms detected.

You can view the attacker and target IP addresses from where the attack was generated when GTP feature is enabled. The alerts can be viewed in Attack Log which also displays the details of the attack.

The inner attacker and target IP address as displayed in the alert
The inner attacker and target IP address as displayed in the alert