The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling dropper detection

Prev Next

Use the CLI commands to enable or disable the dropper detection component, which provides another type of static analysis on the Network Security appliance. This component allows the Network Security appliance to identify malicious files that might have installed additional types of malware on your system. A dropper is not associated with any file extensions, and it is often part of a spearphishing attempt. The Network Security appliance sends the dropper files that matched the first ten MD5 checksums to the Dynamic Threat Intelligence (DTI) Cloud for further analysis. When the dropper detection component is disabled, the Network Security appliance does not send the dropper files to the DTI Cloud.

After you have configured the appliance to detect dropper files using the CLI, you can view the analysis of the results on the > Alerts page in the Web UI.

Note

You can enable or disable dropper detection only using the CLI. This component is enabled by default.

You cannot enable dropper detection using the sensor CLI.

Because the Intelligent Virtual Execution - Server compute node performs static analysis on submitted malware samples, the output fields for each static analysis tool are not displayed for the show static-analysis config command on the sensor.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A connection to the DTI Cloud

  • Verify that static analysis is enabled on the appliance. Use the show static-analysis config command.

  • Verify that AV-Suite integration is enabled on the appliance. Use the show static-analysis config command.