The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Response actions

Prev Next

Trellix IPS allows you to detect malware in the monitored traffic by configuring a malware policy, suited for your enterprise/environment, in the Manager. The malware policy can be configured per interface. The policy can be configured for both inbound and outbound traffic. The same policy can be applied to both, or, separate policies can be applied to inbound and outbound traffic.

When a Sensor detects activity to be in violation of a configured policy, a preset response from the Sensor is integral to the protection or prevention process. Proper configuration of responses is crucial to maintaining effective protection.

Note

  • Trellix recommends the following for optimum performance.

    • The Advanced Malware policies be configured only on the external (internet facing Sensors) and not on the internal ones.

      • Save malicious files, only if the number of files traversing the network is huge. Also, save files with a high or very high confidence level. Avoid using the Always save option.

        Trellix IPS Analysis on the Sensor is slower than on NTBA. For high volume deployments enable PDF detection only on NTBA using Gateway Anti-Malware Engine.

  • When Advanced Malware policies are configured there is a performance impact of up to 6 seconds on both the Sensor and the Manager.