The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Integration with Intelligent Virtual Execution (IVX) Engine

Prev Next

Intelligent Virtual Execution (IVX) Engine is a signature-less, dynamic analysis engine that inspects suspicious network traffic to identify attacks that evade traditional signature-based and policy-based defenses. The IVX engine detects zero-day, multiflow, and other evasive attacks with dynamic, signature-less analysis in a safe, virtual environment. It stops infection and compromise phases of the cyberattack kill chain by identifying never-before-seen exploits and malware.

Trellix IPS offers integration capability with Trellix Intelligent Virtual Execution - Server and Trellix Intelligent Virtual Execution - Cloud which utilize IVX engine's technology to perform malware analysis.

Note

At any instance, you can choose to integrate either Trellix VX (IVX appliance) or Trellix IVX Cloud (IVX Cloud) with Trellix IPS, but not both of them together.

Outline of how this integration works — Based on how you have configured the corresponding Advanced Malware policy, the IPS Sensor detects a file upload and/ or download and sends a copy of the file to IVX for analysis. If IVX immediately detects the file to be a malware, the Sensor can block the download. The Manager displays the results of the analysis from IVX.

If IVX requires more time for analysis, the Sensor allows the file to be downloaded. If IVX detects a malware after the file has been downloaded, it informs Trellix IPS, and you can use the Sensor to quarantine the host until it is cleaned and remediated. You can configure the Manager to update all the Sensors about this malicious file. Therefore, if that file is downloaded or uploaded again anywhere in your network, your Sensors would be able to block it.

Note

The Sensor that is integrated with IVX can be deployed in inline, tap, or SPAN mode. However, similar to other malware engines, response actions such as Block and Send TCP Reset might not have the desired effect since the file might have reached the target host.