The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Integration with Multi-Vector Virtual Execution (MVX) Engine

Prev Next

Multi-Vector Virtual Execution (MVX) Engine is a signature-less, dynamic analysis engine that inspects suspicious network traffic to identify attacks that evade traditional signature-based and policy-based defenses. The MVX engine detects zero-day, multiflow, and other evasive attacks with dynamic, signature-less analysis in a safe, virtual environment. It stops infection and compromise phases of the cyberattack kill chain by identifying never-before-seen exploits and malware.

Trellix IPS offers integration capability with Trellix Virtual Execution (VX) appliances which utilize MVX engine's technology to perform malware analysis.

Outline of how this integration works— Based on how you have configured the corresponding Advanced Malware policy, the IPS Sensor detects a file upload and/ or download and sends a copy of the file to MVX for analysis. If MVX immediately detects the file to be a malware, the Sensor can block the download. The Manager displays the results of the analysis from MVX.

If MVX requires more time for analysis, the Sensor allows the file to be downloaded. If MVX detects a malware after the file has been downloaded, it informs Trellix IPS, and you can use the Sensor to quarantine the host until it is cleaned and remediated. You can configure the Manager to update all the Sensors about this malicious file. Therefore, if that file is downloaded or uploaded again anywhere in your network, your Sensors would be able to block it.

Note

The Sensor that is integrated with MVX can be deployed in inline, tap, or SPAN mode. However, similar to other malware engines, response actions such as Block and Send TCP Reset might not have the desired effect since the file might have reached the target host.