The retroactive detection feature allows the ADD Product Series appliance to alert on missed objects when a hash match happens during an unlimited time period against nonmalicious submissions. This feature uses object hashes to alert on missed detections. The appliance receives a list of SHA-256 hashes from the DTI network through security content updates. The hashes are compared against a list of nonmalicious submissions that were retained or missed from the database within an unlimited time period. If the hash is detected as malicious, the ADD Product Series appliance generates a retroactive alert for a malware object or a riskware object. The submission status for a retroactive alert is marked as dti_detection in the output of the show submission id command.
Note
Retroactive alerts for objects require a one-way, one-way with override, or two-way CONTENT_UPDATES license. Retroactive alerts for URLs identified by the Trellix Advanced URL Defense (FAUDE) service require a one-way with override or two-way CONTENT_UPDATES license. See the Network Security System Administration Guide for information about overriding a one-way CONTENT_UPDATES license.
Note
You can view the status of retroactive detection only using the CLI.
Prerequisites
Administrator, Monitor, or Analyst access to the ADD Product Series appliance
An established connection to the Internet
Validate DTI access on the ADD Product Series appliance by using the show fenet status command. For details about how to validate DTI access, see the Network Security System Administration Guide.