The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Malware Policy

Prev Next

This URL updates the malware policy details.

Resource URL

PUT /malwarepolicy/<policy_id>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
policy_id Malware policy id Number Yes

Payload Request Parameters:

Field Name Description Data Type Mandatory
properties Basic properties of the malware policy Object Yes
scanningOptions List of scanning options per file type Array Yes

Details of properties:

Field Name Description Data Type Mandatory
policyName Policy name String Yes
description Description String No
domainId Domain id Number Yes
lastModifiedTime Last modified time String Yes
lastModifiedUser Last user that modified the policy String Yes
isEditable Is policy editable Boolean Yes
visibleToChild Is the policy visible to child Boolean Yes
protocolsToScan List of protocols supported Array No

Details of object in protocolsToScan:

Field Name Description Data Type Mandatory
protocolName Protocol name String Yes
protocolNumber Protocol number Number Yes
enabled Protocol status Boolean Yes

Details of object in scanningOptions:

Field Name Description Data Type Mandatory
fileType Type of the file String Yes
malwareEngines List of malware engines supported Array Yes
actionThresholds Action threshold details Object Yes
maximumFileSizeScannedInKB Maximum file size scanned in KB Number Yes

Details of object in malwareEngines:

Field Name Description Data Type Mandatory
name Malware engine name String Yes
status Status can be DISABLED/UNCHECKED/CHECKED String Yes
id Malware engine id Number Yes

Details of actionThresholds:

Field Name Description Data Type Mandatory
alert Alert to be sent, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes
block Blocking settings, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes
sendTcpReset Send TCP reset, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes
saveFile Save file can be "DISABLED" / "ALWAYS" /"VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes
addToBlockList Add to blocklist can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Update status Number

Example

Request

PUT https://%3CNSM_IP%3E/sdkapi/malwarepolicy/301

PUT https://<NSM_IP>/sdkapi/malwarepolicy/301

    {
       "properties":
       {
           "policyName": "Test",
           "description": "Add Malware Policy",
           "domainId": 0,
           "visibleToChild": true,
           "protocolsToScan":
           [
               {
                   "protocolName": "HTTP",
                   "protocolNumber": 16,
                   "enabled": true
               },
               {
                   "protocolName": "SMTP",
                   "protocolNumber": 12,
                   "enabled": true
               }
           ]
       },
       "scanningOptions":
       [
           {
               "fileType": "Executables",
               "maximumFileSizeScannedInKB": 5120,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": " Blocklist and Allowlist",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "CHECKED"
                   },
                   {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                             }
               ],
               "actionThresholds":
               {
                   "alert": "LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
                   "addToBlockList": "DISABLED"
               }
           },
           {
               "fileType": "MS Office Files",
               "maximumFileSizeScannedInKB": 1024,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "DISABLED"
                   },
                   {
                       "name": "Blocklist and Allowlist ",
                       "id": 2,
                       "status": "CHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "CHECKED"
                   },
                   {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "MEDIUM",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
                   "addToBlockList": "DISABLED"
               }
           },
           {
               "fileType": "PDF Files",
	     "maximumFileSizeScannedInKB": 1024,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": " Blocklist and Allowlist ",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "CHECKED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "CHECKED"
                   },
  	        {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
	         "addToBlockList": "DISABLED"
               }
           },
           {
               "fileType": "Compressed Files",
	     "maximumFileSizeScannedInKB": 5120,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "DISABLED"
                   },
                   {
                       "name": " Blocklist and Allowlist ",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "UNCHECKED"
                   },
	        {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
	         "addToBlockList": "DISABLED"
               }
           },
	{
               "fileType": "Android Application Package",
	     "maximumFileSizeScannedInKB": 2048,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "CHECKED"
                   },
                   {
                       "name": " Blocklist and Allowlist ",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "DISABLED"
                   },
  	        {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
	         "addToBlockList": "DISABLED"
               }
           },
           {
               "fileType": "Java Archive",
	     "maximumFileSizeScannedInKB": 2048,
               "malwareEngines":
               [
                   {
                       "name": "GTI File Reputation",
                       "id": 1,
                       "status": "DISABLED"
                   },
                   {
                       "name": " Blocklist and Allowlist ",
                       "id": 2,
                       "status": "UNCHECKED"
                   },
                   {
                       "name": "PDF Emulation",
                       "id": 8,
                       "status": "DISABLED"
                   },
                   {
                       "name": "NTBA",
                       "id": 16,
                       "status": "UNCHECKED"
                   },
	        {
		   "name": "Advanced Threat Defense",
    		   "id": 64,
		   "status": "CHECKED"
                   }
               ],
               "actionThresholds":
               {
                   "alert": "VERY_LOW",
                   "block": "HIGH",
                   "sendTcpReset": "HIGH",
                   "saveFile": "DISABLED",
	         "addToBlockList": "DISABLED"
               }
           }
 
       ]
    } 

Response

 {
       "status": 1
    } 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 1105 Invalid domain
2 404 2501 Invalid advanced malware policy id/ policy not visible to this domain
3 400 2508 Malware policy name is required
4 400 2509 Invalid protocol list
5 400 2512 Policy provided is not up to date
6 400 2513 Name must contain only letters, numerical, spaces, commas, periods, hyphens or underscore
7 400 2514 Name already in use
8 400 2515 Default malware policy cannot be updated
9 400 2516 Length of name field cannot exceed 40 characters
10 400 2517 Length of description field cannot exceed 149 characters