The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Python-based static analysis

Prev Next

By default, the Intelligent Virtual Execution - Server appliance performs static analysis on submitted malware samples by using a combination of generic and file type-specific YARA rules and other file type-specific analysis techniques. This feature is called Python-based static analysis.

The Intelligent Virtual Execution - Server appliance returns static analysis results to the originating sensor, where the information can be viewed at the Alerts > Alerts page on the sensor Web UI (or the Alerts > Web MPS > Alerts page on the Central Management System Web UI, if the sensor is under Central Management System management).