The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Riskware

Prev Next

The riskware detection feature allows you to identify files that are similar to malware but are not intended to be malicious. A file that is not a threat might display behavior that might affect threat detection, such as installing unwanted programs, modifying system settings, or reducing the overall performance of the appliance. Types of riskware include Potentially Unwanted Programs (PUPs), Potentially Unwanted Applications (PUAs), adware, and hacker tools. This feature allows you to easily distinguish between malicious files and riskware on the Network Security appliance. You can configure optional riskware detection so that the Multi-Vector Virtual Execution (MVX) engine does not mark the riskware files as malicious, and the files will be excluded from further analysis. The submission status for a riskware alert is marked as Riskware in the output of the show submission id command.

The riskware detection feature is enabled by default on the appliance. You can choose to disable the Trellix riskware rules and enable a single or multiple custom riskware policy rules using the Web UI or CLI. When you enable at least one matched policy rule on the Network Security appliance, you can have the appliance generate a riskware alert on a nonmalicious submission.

On a Network Security sensor or sensor-enabled Network Security integrated appliance, the Intelligent Virtual Execution - Server compute node uses YARA, an open-source malware analytic tool, to identify and classify malware samples in a TrellixMVX deployment.

On a Network Security sensor or sensor-enabled Network Security integrated appliance, static analysis tools are not available. The Intelligent Virtual Execution - Server compute node performs static analysis on submitted malware samples in a TrellixMVX deployment. The Intelligent Virtual Execution - Server compute node returns the results of the static analysis over the SSH connection to the sensor. Therefore, you cannot enable AV-Check and AV-Suite integration on the sensor.

This section covers the following information about configuring riskware analysis: