The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Malware

Prev Next

You can add malware attacks to the malware policy generated from an admin domain. This policy will be updated for that admin domain only.

Steps:

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.

  2. Select the alert, click Other Actions at the bottom of the page.

  3. Select Update Policy, and click (Malware) /<Admin Domain Name>/<Malware Policy>.

    The <Attack Name> panel opens.

  4. Make the required changes to the policy settings and click Update.

    The attack is added to the malware policy of that admin domain.

    To view/edit the attack added to the malware policy:

    1. Navigate to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware.

    2. Double-click on the policy.

      The Advanced Malware page opens.

    Note

    The attacks added to the policies do not come into effect immediately. You have to update the Sensor for a policy update from Deploy Pending Changes.

    For more information on malware policies, see the section Advanced Malware Policies.