The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Retroactive Detection

Prev Next

The retroactive detection feature allows the ADD Product Series appliance to alert on missed objects when a hash match happens during an unlimited time period against nonmalicious submissions. This feature uses object hashes to alert on missed detections. The appliance receives a list of SHA-256 hashes from the DTI network through security content updates. The hashes are compared against a list of nonmalicious submissions that were retained or missed from the database within an unlimited time period. If the hash is detected as malicious, the ADD Product Series appliance generates a retroactive alert for a malware object or a riskware object. The submission status for a retroactive alert is marked as dti_detection in the output of the show submission id command.

Note

Retroactive alerts for objects require a one-way, one-way with override, or two-way CONTENT_UPDATES license. Retroactive alerts for URLs identified by the Trellix Advanced URL Defense (FAUDE) service require a one-way with override or two-way CONTENT_UPDATES license. See the Network Security System Administration Guide for information about overriding a one-way CONTENT_UPDATES license.

Note

You can view the status of retroactive detection only using the CLI.

Prerequisites

  • Administrator, Monitor, or Analyst access to the ADD Product Series appliance

  • An established connection to the Internet

  • Validate DTI access on the ADD Product Series appliance by using the show fenet status command. For details about how to validate DTI access, see the Network Security System Administration Guide.