The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage Advanced Malware policies

Prev Next

You can perform the following operations on an existing Advanced Malware policy.

Operation Description
View Advanced Malware policies The Advanced Malware policies page allows you to view the Malware policies that have been assigned to the various resources of your Trellix IPS. Policies are listed per the Sensor, interface, and subinterface. From the root admin domain, you can see policies assigned to all child domains. For non-root parent domains, you only see the assigned policies in your parent and child domains. For child domains, you only see the policies assigned to the resources in your domain. Select Policy → <Admin Domain Name> → Policy Types → Advanced Malware to view the assigned Malware policies.
Edit an Advanced Malware policy Editing an Advanced Malware policy allows you to make the changes necessary to match the policy with the traffic you are monitoring. Editing a policy permanently changes that policy. If you intend to make slight changes to a policy but want to save it under a different name, try cloning an Advanced Malware policy.

To edit an Advanced Malware policy:

  1. Select Policy → <Admin Domain Name> → Policy Types → Advanced Malware.

    The Advanced Malware policies are listed.

  2. Double click the policy to edit.
  3. Edit the policy parameters.
  4. Click Save.
Clone an Advanced Malware policy Cloning duplicates an existing policy, and is similar to a "save as" function. You can edit a Trellix IPS-provided policy. However, if you want to edit a copy of a policy, you can clone any existing policy to further refine the policy for application in a new environment. You can clone a provided policy, save it under a new name, and customize it for your unique environment.
  1. Select Policy → <Admin Domain Name> → Policy Types → Advanced Malware.

    The policies are listed.

  2. Select the policy you want to clone.
  3. Click .
  4. Type a new name for the policy, if required and edit the policy parameters.
Delete an Advanced Malware policy To delete an Advanced Malware policy you have created:
  1. Select Policy → <Admin Domain Name> → Policy Types → Advanced Malware.

    The Advanced Malware policies are listed.

  2. Select the policy to be deleted.
  3. Click .
  4. Click Yes to confirm the deletion.

    You cannot delete a currently applied policy.

Export an Advanced Malware policy You can export and save one or more Advanced Malware policies into a file.
  1. Select Policy → <Admin Domain Name> → Intrusion Prevention → Advanced → Policy Export → Advanced Malware.

    The existing Advanced Malware policies are listed.

  2. Select one or more policies to be exported.
  3. Click Export. You are prompted to specify the location to save the file.

    The policy is saved in an XML format in the specified location.

Import an Advanced Malware policy You can import an Advanced Malware policy from a saved file.
  1. Select Policy → <Admin Domain Name> → Intrusion Prevention → Advanced → Policy Import → Advanced Malware.

    To skip importing duplicate policy definition, select Skip duplicate policy definitions.

  2. Browse to the file location.
  3. Click Import. The import status is displayed.