The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling riskware detection custom policy rules

Prev Next

You can enable or disable riskware detection custom policy rules by using the Network Security appliance Web UI or CLI:

When you enable a particular policy rule based on riskware detection on the Network Security appliance, traffic matching the submission is marked as custom riskware and it will be excluded from further analysis. When you disable a particular policy rule based on riskware detection, traffic matching the submission is not marked as custom riskware. After you have configured the Network Security appliance to detect a riskware custom policy rule, you can view the analysis results on the Alerts > Riskware page in the Web UI.

Note

Riskware detection custom policy rules support only Riskware Object alerts on the Network Security appliance.

For details about how to view the matched riskware alerts, see Viewing riskware alert details in the Web UI.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • An established connection to the Internet

  • A connection to the DTI Cloud

  • Download and install the latest security content with new riskware policy rules by using the fenet security-content apply-update command, For details about how to update security content, see the Network Security System Administration Guide.