The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Task list for managing riskware

Prev Next

Complete the steps for managing riskware in the following order:

  1. (Optional) Verify that the Local Binary Analysis (BA) Signers Whitelist feature is configured on the Network Security to make sure that the Portable Executable (PE) files are from a list of trusted companies for riskware detection. For details about how to configure the Local BA Signers Whitelist feature, see Local BA signers whitelist.

  2. (Optional) Enable AV-Check on the appliance. For details about how to enable AV-Check, see Enabling or disabling AV-check.

  3. (Optional) Verify that AV-Suite integration is enabled on the appliance. Use the show static-analysis config command.

  4. (Optional) Verify that the appliance is configured to perform YARA analysis. Use the show static-analysis config command.

  5. Enable riskware detection, if necessary (riskware detection is enabled by default). For details, see Enabling or disabling riskware detection using the Web UI or Enabling or disabling riskware detection using the CLI.

  6. Track the number of riskware alerts detected on the Network Security by using the Alerts Summary widget in the dashboard.

  7. View the results on the Riskware alerts page in the Web UI. For details, see Viewing riskware alert details in the Web UI.

  8. (Optional) Download the XML for a riskware alert. See Downloading XML for riskware alerts using the Web UI.