The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Malware Alerts

Prev Next

This URL get the list malware alerts for the malware file hash.

Resource URL

GET /domain/<domain_id>/malwaredownloads/ filehash/<filehash>?duration=<duration>&resultType=<resultType>&confidenceType=<confidenceType>&includeChildDomain=<includeChildDomain>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domain

Domain id

Number

Yes

duration

Duration can be:

  • LAST_5_MINUTES

  • LAST_1_HOUR

  • LAST_6_HOURS

  • LAST_12_HOURS

  • LAST_24_HOURS

  • LAST_48_HOURS

  • LAST_7_DAYS

  • LAST_14_DAYS

String

No

resultType

Result type can be:

  • ANY_RESULT

  • BLOCKED

  • UNBLOCKED

String

No

confidenceType

Confidence type can be:

  • ANY_MALWARE_CONFIDENCE

  • VERY_HIGH_MALWARE_CONFIDENCE

  • HIGH_MALWARE_CONFIDENCE

  • LOW_MALWARE_CONFIDENCE

  • MEDIUM_MALWARE_CONFIDENCE

  • VERY_LOW_MALWARE_CONFIDENCE

String

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

malwareAlertDetailsList

List of malware alert detail defined in the domain

Array

Details of object in MalwareAlertDetail:

Field Name

Description

Data Type

time

Time stamp

String

attacker

IP details

Object

target

IP details

Object

result

Result

String

protocol

Protocol

String

confidence

Confidence can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN"

String

fileName

File name

String

engine

Engine

String

attackDescription

Attack description

Object

Details of object in attacker/target:

Field Name

Description

Data Type

ipAddress

IP address

String

country

Country

String

Details of object in attackDescription:

Field Name

Description

Data Type

attackName

Attack name

String

result

Result can be: "ATTACK_SUCCESSFUL"/"INCONCLUSIVE"/" ATTACK_FAILED"/"ATTACK_BLOCKED"/" NOT_APPLICABLE"/" DOS_BLOCKING_ACTIVATED"/" BLOCKING_SIMULATED_ATTACK_SUCCESSFUL"/ "BLOCKING_SIMULATED_INCONCLUSIVE"/" BLOCKING_SIMULATED_ATTACK_FAILED"/" BLOCKING_SIMULATED_NOT_APPLICABLE"

String

direction

Direction can be: "INBOUND"/" OUTBOUND"/" UNKNOWN"/" BOTH"

Example

Request

GET https://<NSM_IP>/domain/0/malwaredownloads/filehash/4e1b0fab3e49832570eedeb7a54c4d11

Response

  {
    "malwareAlertDetailsList": [
        {
            "time": "Dec 27 13:24 IST",
            "attacker": {
                "ipAddress": "1.1.1.2",
                "country": "---"
            },
            "target": {
                "ipAddress": "1.1.1.1",
                "country": "---"
            },
            "result": "Inconclusive",
            "protocol": "smtp",
            "confidence": "VERY_HIGH",
            "fileName": "",
            "engine": "Trellix IPS Analysis",
            "attackDescription": {
                "attackName": "MALWARE: Malicious PDF file transfer detected",
                "result": "INCONCLUSIVE",
                "direction": "INBOUND"
            }
        },
        {
            "time": "Dec 27 13:22 IST",
            "attacker": {
                "ipAddress": "1.1.1.2",
                "country": "---"
            },
            "target": {
                "ipAddress": "1.1.1.1",
                "country": "---"
            },
            "result": "Inconclusive",
            "protocol": "smtp",
            "confidence": "VERY_HIGH",
            "fileName": "",
            "engine": "Trellix IPS Analysis",
            "attackDescription": {
                "attackName": "MALWARE: Malicious PDF file transfer detected",
                "result": "INCONCLUSIVE",
                "direction": "INBOUND"
            }
        },
    ]
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

500

1001

Internal error

2

404

1105

Invalid domain

3

404

3401

Invalid file hash value

4

400

3801

Invalid result filter value

5

400

3802

Invalid duration filter value