Use this file to discover all available pages before exploring further.
The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.
A default Next Generation Report called
Top 10 Malware Detections provides details of the detected malware. For a given time period, this report shows the alerts raised for the top 10 most frequently downloaded malware in your network. Therefore, for a given file, you can view the results from various malware engines. However, these results are dependant on the Advanced Malware policy configuration for the period of the report.
Task
In the Manager, select
Analysis → Event Reporting → Next Generation Reports.
From the list of
Saved Reports, select
Default - Top 10 Malware Detections and then click
Run.
Specify the time period for which you want to generate the report in the
Date Options section.
Select the output format of the report from the
Report Format list.
Click
Run.
The default Top 10 Malware Detections report The generated report is displayed.
Column definitions
Column
Definition
Time
The time stamp when a malware engine determined the file to be malicious
Attack Name
The alert raised by the Sensor for the file
Result
The response action taken by the Sensor for the file. For example, the Sensor could have blocked the file download.
Src IP
The source IP address as seen in the traffic for the malware traffic
Dest IP
The target host that is downloading the file
Protocol
The L7 protocol involved. This could be HTTP or SMTP.
Device
The Sensor that detected the file download
File Hash
The MD5 hash value of the file as calculated by the Sensor
Detection Engine
The malware engine that reported the malware
File Malware Confidence
The malware score reported by the malware engine
Layer7 Data
The L7 data associated with the file
Note
The admin domain filter on the main
Analysis tab (provided in the left pane) has no impact on the reports generated. The admin domain filter criteria selected for the reports show data specific to the admin domain selected.
For information how to use the Next Generation Reports, see the section
Next Generation reports in
Trellix Intrusion Prevention System Product Guide.
You can also generate a User Defined report using all of the above columns. For example, you can generate a User Defined report that reports only very-high severity malware detected by Sensors of a particular domain. You must use
Alert Data as the
Data Source when you define the report. For more information on how to generate a User Defined report, see the section
Generate Next Generation user defined reports in
Trellix Intrusion Prevention System Product Guide.