Use the Riskware Policy Settings page to globally enable or disable Trellix riskware detection on the Network Security appliance.
In the Web UI, choose Settings > Riskware Policy.
Select the FireEye Riskware Rules tab.
Click the Alert Only checkbox for FireEye Riskware (Adware/PUP/Spam) to enable riskware alerts.
Click Apply.
Click Yes to confirm.
Verify the status. The FireEye Riskware (Adware/PUP/Spam) rule will have Enabled in the Alert Only column.
hostname (config) # show analysis riskware policy rules
|------------|-----------------------------------------------------------|------------| | Rule ID | Rule | Alert Only | |------------|-----------------------------------------------------------|------------| | 65000 | Jar Files Delivered Via Email Attachment Or Link | Disabled | | 65001 | Encrypted MS Office Document | Disabled | | 65002 | PDF, HWP or MS Office Files With Network Activity | Disabled | . . . | 65037 | Suspicious DAA Archive Delivered via Email | Disabled | | 65038 | Supply Chain Impersonation (8.4x) | Disabled | | | FireEye Riskware (Adware/PUP/Spam) | Enabled | |____________|___________________________________________________________|____________|
Select the FireEye Riskware Rules tab.
Clear the Alert Only checkbox for FireEye Riskware to turn off riskware alerts.
Click Apply. The following message appears:
Trellix recommends that you do not disable Trellix Riskware (Adware/PUP/Spam) rules. Do you want to continue?
Click Yes to confirm.