The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling riskware detection using the Web UI

Prev Next

Use the Riskware Policy Settings page to globally enable or disable Trellix riskware detection on the Network Security appliance.

To enable the Trellix riskware rules for alerts:
  1. In the Web UI, choose Settings > Riskware Policy.

  2. Select the FireEye Riskware Rules tab.

  3. Click the Alert Only checkbox for FireEye Riskware (Adware/PUP/Spam) to enable riskware alerts.

  4. Click Apply.

  5. Click Yes to confirm.

  6. Verify the status. The FireEye Riskware (Adware/PUP/Spam) rule will have Enabled in the Alert Only column.

    hostname (config) # show analysis riskware policy rules
    |------------|-----------------------------------------------------------|------------|
    |    Rule ID |                                                      Rule | Alert Only |
    |------------|-----------------------------------------------------------|------------|
    |      65000 |          Jar Files Delivered Via Email Attachment Or Link |   Disabled |
    |      65001 |                              Encrypted MS Office Document |   Disabled |
    |      65002 |         PDF, HWP or MS Office Files With Network Activity |   Disabled |
    .
    .
    .
    |      65037 |                Suspicious DAA Archive Delivered via Email |   Disabled |
    |      65038 |                         Supply Chain Impersonation (8.4x) |   Disabled |
    |            |                      FireEye Riskware (Adware/PUP/Spam)    |    Enabled | 
    |____________|___________________________________________________________|____________|
    			
To disable the Trellix riskware rules for alerts:
  1. Select the FireEye Riskware Rules tab.

  2. Clear the Alert Only checkbox for FireEye Riskware to turn off riskware alerts.

  3. Click Apply. The following message appears:

    Trellix recommends that you do not disable Trellix Riskware (Adware/PUP/Spam) rules. Do you want to continue?
  4. Click Yes to confirm.