Riskware detection custom policy rules help you to identify objects by suspicious file types and mark them as riskware. The Network Security appliance receives a list of updated riskware policy rules when the system checks for new security content from the DTI Cloud. Both the rule ID and rule name are unique. Analysis is performed against all matched rules.
When you enable at least one matched policy rule on the Network Security appliance, the appliance generates a riskware alert on a nonmalicious submission. No further analysis is performed. The submission status for a riskware alert of a policy rule is marked as Custom Riskware in the output of the show submission id command.
The following table describes some of the riskware detection custom policy rules that trigger a riskware alert. You can see the full list of riskware policy rules in the Web UI in Settings > Riskware Policy.
Riskware Policy Rule | Trigger Condition |
|---|---|
65005 Low Confidence Custom Yara Rule Weights 0-50 | Custom YARA rules applied reach total weight between 0 and 50. See About YARA rules. |
65006 High Confidence Custom Yara Rule Weights 51-99 | Custom YARA rules applied reach total weight between 51 and 99. See About YARA rules. |
65009 Non Executable file Connecting to Non-Standard High Port | Non-executable files that connect to ports above 1024 |
65012 MS Office Document With Macro Activity Dropping a exe file | Microsoft Office files have macro activity that writes executable files |
65013 Password From Web Forms Sent as Plaintext Http_Request | Email Web forms have passwords that are sent as plain-text HTTP requests |
65020 MS Office Document running Flash Events | Microsoft Office documents are running Flash events |
65021 MS Office Document With Password Protected Macro | Microsoft Office documents have a password-protected macro |
65031 Potential Risky ScreenSaver Indicator | Files have a risky screensaver indicator |
65035 Low Confidence Malware Guard on NX |
Note
Riskware detection custom policy rule configuration is disabled by default.