AV-Suite is a cloud-based detection service that stores verdicts for both malicious (blacklist) and nonmalicious (whitelist) objects. Information about a sample is sent to AV-Suite by the Email Security - Server appliance. This service is accessed by the Email Security - Server appliance using the AV-Suite Integration feature to provide verdicts based on advanced detection analytics in the cloud. Because dynamic analysis can be slow, AV-Suite helps to ensure the optimal appliance and analysis engine performance by not submitting samples that were whitelisted by AV-Suite to dynamic analysis.
Before an object is submitted to the Email Security - Server appliance for dynamic analysis, the appliance queries the AV-Suite server for a verdict. If a clean verdict is returned from AV-Suite for the file, the Email Security - Server appliance will not analyze the file for malicious content and the appliance will not perform dynamic analysis for this sample. If a malicious or riskware verdict is returned from AV-Suite, the Email Security - Server appliance will still perform dynamic analysis to generate an OS Change report.
When retroactive detection is enabled on the Email Security - Server appliance, the appliance can alert on previously undetected objects. The Email Security - Server appliance can alert on previously undetected objects when a new verdict is generated for that object within the DTI Cloud. For details about retroactive detection, see ??? .
Task List for Managing AV-Suite
Complete the steps for managing AV-Suite in the following order:
Log in to the CLI.
Validate DTI access on the Email Security - Server appliance by using the
show fenet statuscommand. For details about how to validate DTI access, refer to the Email Security - Server System Administration Guide.Verify that
unity.fireeye.comis the DTI server address for AV-Suite to store both blacklist and whitelist object hashes and analysis results. Use theshow fenet dti configurationcommand. For details about how to set the DTI server address for AV-Suite, refer to the Email Security — Server System Administration Guide.Important
By default, this address for managed appliances is the address of the managing Central Management System appliance. For more effective detection and remediation, Trellix recommends a direct connection to
unity.fireeye.com.Verify that AV-Suite integration is enabled and that AV-suite version 6 is configured. Use the
show static-analysis configcommand. For details about AV-Suite integration, see Enabling or disabling AV-Suite integration using the CLI.Enable static analysis and AV-Suite integration on whitelist submissions. For details about how to enable AV-Suite Integration on whitelist submissions, see Enabling or disabling AV-Suite integration on whitelist submissions using the CLI.
Enable retroactive detection from AV-Suite. Use the
analysis retro-hunt enablecommand. For details about how to enable retroactive detection from AV-Suite, see Enabling or disabling Retroactive Detection from AV-Suite.Configure the settings for retroactive detection from AV-Suite. For details about how to configure the settings for retroactive detection from AV-Suite, see Configuring Retroactive Detection from AV-Suite.