The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manager reports for malware detections

Prev Next

A default Next Generation Report called Top 10 Malware Detections provides details of the detected malware. For a given time period, this report shows the alerts raised for the top 10 most frequently downloaded malware in your network. Therefore, for a given file, you can view the results from various malware engines. However, these results are dependant on the Advanced Malware policy configuration for the period of the report.

Task

  1. In the Manager, select Analysis → Event Reporting → Next Generation Reports.
  2. From the list of Saved Reports, select Default - Top 10 Malware Detections and then click Run.
  3. Specify the time period for which you want to generate the report in the Date Options section.
  4. Select the output format of the report from the Report Format list.
  5. Click Run.
    The default Top 10 Malware Detections report


    The generated report is displayed.
    Column definitions
    Column Definition
    Time The time stamp when a malware engine determined the file to be malicious
    Attack Name The alert raised by the Sensor for the file
    Result The response action taken by the Sensor for the file. For example, the Sensor could have blocked the file download.
    Src IP The source IP address as seen in the traffic for the malware traffic
    Dest IP The target host that is downloading the file
    Protocol The L7 protocol involved. This could be HTTP or SMTP.
    Device The Sensor that detected the file download
    File Hash The MD5 hash value of the file as calculated by the Sensor
    Detection Engine The malware engine that reported the malware
    File Malware Confidence The malware score reported by the malware engine
    Layer7 Data The L7 data associated with the file

    Note

    The admin domain filter on the main Analysis tab (provided in the left pane) has no impact on the reports generated. The admin domain filter criteria selected for the reports show data specific to the admin domain selected.

    • For information how to use the Next Generation Reports, see the section Next Generation reports in Trellix Intrusion Prevention System Product Guide.
    • You can also generate a User Defined report using all of the above columns. For example, you can generate a User Defined report that reports only very-high severity malware detected by Sensors of a particular domain. You must use Alert Data as the Data Source when you define the report. For more information on how to generate a User Defined report, see the section Generate Next Generation user defined reports in Trellix Intrusion Prevention System Product Guide.