The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Malware Policy

Prev Next

This URL gets the malware policy details.

Resource URL

GET /malwarepolicy/<policy_id>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

Policy_id

Policy id

Number

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

properties

Basic properties of the malware policy

Object

scanningOptions

List of scanning options per file type

Array

Details of properties:

Field Name

Description

Data Type

policyId

Policy id

Number

policyName

Policy name

String

description

Description

String

domainId

Domain Id

Number

lastModifiedTime

Last modified time

String

lastModifiedUser

Last user that modified the policy

String

isEditable

Is policy editable

Boolean

visibleToChild

Is the policy visible to child

Boolean

protocolsToScan

List of protocols supported

Array

Details of object in protocolsToScan:

Field Name

Description

Data Type

protocolName

Protocol name

String

protocolNumber

Protocol number

Number

enabled

Protocol status

Boolean

Details of object in scanningOptions:

Field Name

Description

Data Type

fileType

Type of the file

String

malwareEngines

List of malware engines supported

Array

actionThresholds

Action threshold details

Object

Details of object in malwareEngines:

Field Name

Description

Data Type

name

Malware engine name

String

status

Status can be DISABLED/UNCHECKED/CHECKED

String

id

Malware engine id

Number

Details of actionThresholds:

Field Name

Description

Data Type

alert

Alert to be sent, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH"

String

block

Blocking settings, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH"

String

sendTcpReset

Send TCP reset, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH"

String

saveFile

Save file, can be "DISABLED" / "ALWAYS" /"VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH"

String

Example

Request

GET https://<NSM_IP>/sdkapi/malwarepolicy/301

Response

   {
       "properties":
       {
           "policyId": 301,
           "policyName": "Test",
           "description": "",
           "domainId": 0,
           "lastModifiedTime": "2012-10-08 13:39:56",
           "lastModifiedUser": "admin",
           "isEditable": true,
           "visibleToChild": true,
           "protocolsToScan":
           [
               {
                   "protocolName": "HTTP",
                   "protocolNumber": 16,
                   "enabled": true
               },
               {
                   "protocolName": "SMTP",
                   "protocolNumber": 12,
                   "enabled": true
               }
           ]
       },
       "scanningOptions":
       [
           {
               "fileType": "Executables",
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "CHECKED"
                   },
                   {
                       "name": "Custom Fingerprints",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Analysis",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "Anti-Malware Analysis",
                       "id": 16,
                       "status": "UNCHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED"
               }
           },
           {
               "fileType": "MS Office Files",
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "DISABLED"
                   },
                   {
                       "name": "Custom Fingerprints",
                       "id": 2,
                       "status": "CHECKED"
                   },
                   {
                       "name": "PDF Analysis",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "Anti-Malware Analysis",
                       "id": 16,
                       "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "MEDIUM",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED"
               }
           },
           {
               "fileType": "PDF Files",
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "CHECKED"
                   },
                   {
                       "name": "Custom Fingerprints",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Analysis",
                       "id": 8,
                       "status": "CHECKED"
                   },
                   {
                       "name": "Anti-Malware Analysis",
                       "id": 16,
                       "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED"
               }
           },
           {
               "fileType": "Compressed Files",
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "DISABLED"
                   },
                   {
                       "name": "Custom Fingerprints",
                       "id": 2,
                       "status": "DISABLED"
                   },
                   {
                       "name": "PDF Analysis",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "Anti-Malware Analysis",
                       "id": 16,
                       "status": "UNCHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED"
               }
           }
       ]
    }

Error Information

Following error code is returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

2501

Invalid advanced malware policy id/ policy not visible to this domain