The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes for upgrading from 9.1, 9.2, or 10.1 to 10.1.5.190

Prev Next

Integration with Multi-Vector Virtual Execution (MVX) Engine

Multi-Vector Virtual Execution (MVX) Engine is a signature-less, dynamic analysis engine that inspects suspicious network traffic to identify attacks that evade traditional signature-based and policy-based defenses. The MVX engine detects zero-day, multiflow, and other evasive attacks with dynamic, signature-less analysis in a safe, virtual environment. It stops infection and compromise phases of the cyberattack kill chain by identifying never-before-seen exploits and malware.

Starting with this release of 10.1, Trellix IPS offers integration capabilities with Trellix Virtual Execution (VX) appliances which utilize Multi-Vector Virtual Execution (MVX) engine's technology to perform malware analysis. MVX serves as an additional malware engine for all the supported file types in the Advanced Malware Policies. You can select this engine along with any of the other malware engines.

A list of Sensor CLI commands have been added to support the MVX engine integration.

The following Sensor CLI commands are added:

Normal Mode
Command Description
show mvx config This command displays the MVX configuration details
show mvx stats This command displays statistics specifics to MVX engine analysis.
show mvx status This command displays the connection status of the MVX engine.

A list of Sensor CLI commands have been updated to support the MVX engine integration.

The following Sensor CLI commands are updated:

Normal Mode
Command Description
clearmalwarecache This command now allows users to clear MVX related cache entries made in the Sensor.
clrstat This command now clears all the statistics counters in the Sensor including the MVX counters.
show malwareenginestats This command now displays the malware engine statistics related to MVX.
show malwarefilestats This command now displays the malware file statistics related to MVX.

The following Sensor CLI commands are updated:

Debug Mode
Command Description
set malwareEngine This command now allows users to enable or disable MVX engine.
show malwareclientstats The command now displays the malware client statistics in the scan engines including MVX engine for all supported file types.
show malwareEngine status This command now displays the status of the MVX engine.
show malwareserverstats This command now displays the malware server statistics in all scan engines including MVX engine for all supported file types.

Sensor Commands

Along with MVX commands documented above, the following Sensor CLI commands are added:

Normal Mode
Command Description
clear afo dst-mac This command clears the previously configured destination MAC address on the specified port-pairs.
set afo port-pair and dst-mac This command is used to configure the destination MAC address in the heartbeat packets sent by the Active Fail-Open (AFO) kit. These packets will be used by Sensor to determine the status of the AFO kit.
show afo status This command displays the MAC address detected in the Heartbeat packets sent by the Active Fail-Open (AFO) kit, followed by the current AFO kit state.