The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Microsoft Office File Deep Inspection

Prev Next

With Microsoft Office File Deep Inspection, compressed Microsoft Office files in HTTP traffic are inspected. Further, the traffic segments are decompressed for detection of any threats and anomalies.

With Microsoft Office File Deep Inspection, compressed Microsoft Office files in HTTP traffic are inspected.

Microsoft Office version 2007 and later uses Office Open XML format, a zipped XML based file format. The zipped file contains multiple files upon extraction. This format is compact and reduces bandwidth consumption and transfer time. However, attackers use this to avoid detection of malicious payload.

When Microsoft Office File Deep Inspection feature is enabled, it instructs the Sensor to inspect traffic segments for the Microsoft Office files (i.e. docx, .pptx, or.xlsx). Initially, the docx, .pptx, or.xlsx files identified are scanned using the Microsoft Office File Deep Inspection signatures. These signatures identify the files that are to be decompressed. The decompressed files are inspected further for attack identification. Post inspection, when an attack is detected, the malicious files are blocked, and alerts are generated in the Manager. The process of Microsoft Office File Deep Inspection in the Sensors is achieved using advanced signature sets with multi-level threat detection mechanism. These signature sets are customized and cannot be created using UDS framework.

Points for consideration:

  • Microsoft Office File Deep Inspection feature is supported only for .docx, .pptx, and .xlsx file extensions in HTTP traffic on NS-series Sensor version 10.1 and later.

  • Microsoft Office File Deep Inspection is disabled by default.

  • To enable Microsoft Office File Deep Inspection, HTTP Response Traffic Scanning should be enabled.

  • Microsoft Office File Deep Inspection feature detects malicious hostnames present in URLs mentioned in any .docx, .pptx, or .xlsx files submitted for inspection. The files downloaded through a URL in the Microsoft Office files are inspected as new files.

  • Microsoft Office File Deep Inspection is supported in inline and span modes for both Intrusion Prevention Systems (IPS) and Intrusion Detection Systems (IDS).

  • Microsoft Office File Deep Inspection feature impacts the Sensor performance depending on the number of Microsoft Office files (i.e. docx, .pptx, or.xlsx) in the traffic.

  • The Microsoft Office files (i.e. docx, .pptx, or.xlsx) can have any number of files embedded within them using Office Open XML format. While inspecting such Microsoft Office files, the Sensor scans all embedded files, but only a few files are selectively decompressed using Microsoft Office File Deep Inspection signatures and inspected further for attack detection.

  • Nested decompression is not supported in the following situations:

    1. When a Microsoft Office XML file is zipped inside another .zip file.

    2. When the traffic flowing through the network is zipped. That is, when traffic to be inspected is completely zipped and contains the Microsoft Office files (i.e.docx, .pptx, or.xlsx) files in the zipped content.

  • User defined signatures, Trellix IPS Snort, and Suricata Snort cannot be used to create Microsoft Office File Deep Inspection signatures.

  • To disable any Microsoft Office attack, you should disable the correlation attack for the respective attack in IPS policies.

  • Microsoft Office File Deep Inspection and Malware analysis features are mutually exclusive. If Malware Analysis is enabled, the malware analysis engine takes precedence over Microsoft Office File Deep Inspection. Microsoft Office File Deep Inspection feature considers files in the traffic as zipped archives unlike Advance Malware Inspection feature where the files are inspected as single executables.