The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Malware events and IPS events

Prev Next

  • Malware events

  • Malware alerts

  • IPS events

  • IPS alerts for MVX-correlated IPS events

  • A limitation of MVX correlation of IPS events

Malware events

A standard Network Security appliance automatically monitors the network traffic, checking for client-targeting malware delivered via HTTP and detecting suspicious callbacks over multiple protocols. Using standard Network Security security content rules, the appliance performs malware detection on traffic that passes through all monitoring interfaces.

When operating in standard mode without IPS features activated, the Network Security appliance uses all the malware detection security content rules—FireEye-provided, locally generated, and dynamically generated signature-based rules—in the appliance rules database. If you have incorporated custom security content rules for malware detection, the Network Security appliance also applies those rules to all monitoring interfaces.

Malware alerts

Malware events detected by the standard Network Security signature-based rules engine identify various incidents as they correlate to specific phases of the malware infection life cycle. The platform sends the suspected exploits to the Multi‑Vector Virtual Execution (MVX) engine for detonation and second stage analysis. The MVX engine provides dynamic, real-time analysis of advanced malware. The MVX engine captures and confirms zero-day and targeted advanced persistent threat (APT) attacks by detonating suspicious files and Web objects within virtual machine environments. Because the MVX engine operates in an isolated and virtualized network, this traffic remains internal to the appliance.

Signature-less verification within the purpose-built MVX engine means that the standard Network Security rules for malware detection raise near-zero false positive events. The standard Network Security appliance automatically applies its entire database of standard Network Security rules to network traffic at all appliance monitoring ports with no filtering or other tuning required.

To investigate MVX-verified malware events, you can filter or sort the list of alerts in the Web UI and drill down for more details about specific alerts.

IPS events

If you apply an IPS policy to monitoring interfaces, the system uses IPS rules—in addition to the Trellix-provided and locally generated standard Network Security signature rules—to analyze the traffic passing through those ports. The IPS rules detect traffic patterns that indicate the delivery of potential client-targeting and server-targeting threats to your network over multiple protocols. To investigate suspicious traffic flows identified by IPS rules, you can filter or sort the list in the IPS Events page and drill down for more details about specific events. For details, see About the IPS Events Page and Details for an IPS Event Grouping.

You can configure Network Security notification settings to send IPS event notifications by email, post to Web servers, log messages to remote syslog servers, or send traps to SNMP servers.

IPS alerts for MVX-correlated IPS events

In traditional IPS solutions, signature-based rules for detecting vulnerabilities and exploits generate a high rate of false-positive alerts. IPS platforms significantly reduce false-positive alerts by applying event correlation algorithms to IPS events whenever possible. The algorithms ensure that IPS alerts are limited to IPS events that correlate with attacks verified by standard Network Security features. Event correlation cannot be disabled and is not configurable.

Three Web UI lists tag IPS alerts by displaying an MVX or IPS “badge” in that row.

List

Badge

Entry description

IPS events

icon_ips_badge_mvx.png

An IPS event grouping—IPS events that share the same victim IP address, attacker IP address, signature ID, and (if applicable) VLAN ID—that contains at least one event that correlates with MVX-verified malware

Hosts

icon_ips_badge_ips.png

A malware alert grouping—of alerts that share the same victim and signature rule—that contains at least one alert detected by an IPS rule

Alerts

icon_ips_badge_ips.png

A malware alert grouping—of alerts that share the same signature rule—that contains at least one alert detected by an IPS rule

A limitation of MVX correlation of IPS events

If an IPS event is detected on a monitoring interface configured for inline deployment mode, and if the event was triggered by an IPS rule match on traffic that was blocked, the platform is unable to correlate the IPS event with MVX-verified malware alerts. The blocking action causes all subsequent packets in that session to be dropped, and consequently the signature-based rules engine cannot send objects from the suspicious traffic flow to the MVX engine for confirmation of the client-targeting attack. Without this MVX verification component, the IPS-enabled rules engine cannot determine whether the IPS event qualifies as an IPS alert.