The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Malware inspection on HTTP Upload requests

Prev Next

Trellix Intrusion Prevention System offers malware inspection capabilities for HTTP upload requests generated in the network. The HTTP Upload option is useful in environments where files uploaded through the network need to be scanned.

Selecting HTTP Upload option
Selecting HTTP Upload option


The Sensor has capabilities to scan both HTTP multipart and non-multipart requests for presence of malware.

In case of HTTP requests containing multiparts, malware inspection is supported only on the following multipart Content-Types:

  • Multipart/alternative

  • Multipart/digest

  • Multipart/form-data

  • Multipart/mixed

  • Multipart/parallel

  • Multipart/related

  • Multipart/report

Multipart Content-Types that are currently not supported for inspection are:

  • Multipart/signed

  • Multipart/encrypted

  • Multipart/byteranges

  • Nested Multipart forms

Note

The Sensor does not support the inspection of malware files when files are transferred/uploaded using encoding mechanisms. These encodings are generally indicated by Content-Encoding/Content-Transfer-Encoding/Transfer-Encoding headers. To view the list of file types and their extensions supported for scanning, see the table File scanning options within the sectionAdd an Advanced Malware policy.

Note

For information about the maximum file size that can be scanned, see the table File scanning options within the sectionAdd an Advanced Malware policy.

You can view Layer 7 HTTP data for an alert from the Attack Log by following these tasks:

  1. Navigate to Analysis → <Admin Domain Name> → Malware Files.

  2. Double-click on the malware file hash that is associated with a malicious HTTP request. The Attack Log opens where you can view and analyze alerts related to the selected hash.

  3. Double-click on an alert to view all information related to the attack.

  4. The <Attack Name> panel opens on the right-hand side. Click the Details tab and scroll down to Layer 7 section to view the HTTP fields associated with the alert.

    GUID-FC5C5C6D-0F13-4A49-B273-61758B4A2054-low.png

The HTTP fields displayed under the Layer 7 section vary depending on the HTTP alert you select for examination.

Note

The limit for the number of files uploaded and scanned per single HTTP POST or PUT transaction is 10.

Note

Malware inspection on HTTP requests requires additional system resources and can therefore impact overall Sensor performance.