The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Malware engine caching

Prev Next

Malware scanning engines like Trellix IPS Analysis, and Gateway Anti-Malware have caching capabilities. By default, the IVX and Trellix Intelligent Sandbox malware engine file results are cached.

Once a file is analyzed by IVX or Trellix Intelligent Sandbox, the file results are cached. If the same file is received by the Sensor, it is not sent to these engines for analysis, and the results are retrieved from the cache.

  • The Sensor continues to submit files for analysis to IVX or Trellix Intelligent Sandbox or both (based on malware engines selected) until the file analysis results are complete and stored in the cache.

  • The cache can be purged after a specified duration, which can be configured via CLI.

  • You can use the CLI commands, atdcache autopurge, set atdcachepurge interval hours, and clearmalwarecacheto configure the cache settings. See the CLI commands section for details.