The Trellix Unified Multiflow Engine (FUME) allows the ADD Product Series appliance to send the suspicious URLs or objects to the virtual machine (VM) for a complete analysis. With FUME, the appliance uses multiple code-level static analysis techniques to identify objects (such as PDFs, EXEs, DLLs, or Microsoft Office files) and URLs as malicious that are involved in a multiflow attack. The results of the analysis of malicious objects and URLs are displayed on the Alerts > Alerts page in the Web UI. You can view the network statistics and statistics of malware objects using the CLI. You can also view the details about all the plug-in content versions and different FUME content rule versions using the CLI.
Prerequisites
Administrator or Operator access to the ADD Product Series appliance