Configuring riskware email blocking

Prev Next

You can enable or disable blocking emails based on riskware detected by Trellix Riskware rules by using the Email Security - Server appliance Web UI or CLI:

When you enable riskware detection both to generate a riskware alert and to block an email, the Email Security - Server appliance blocks emails that might be suspicious. In this scenario, a malware object event notification is generated if the sample is detected as riskware. You can view the analysis results on the eAlerts > Alerts page in the Web UI.

Note

Blocking emails based on the riskware detection feature is disabled by default.

Prerequisites

  • Administrator or Operator access to the Email Security - Server appliance

  • An established connection to the Internet

  • A connection to the DTI Cloud

  • Download and install the latest security content with new riskware policy rules by using the fenet security-content apply-update command, For details about how to update security content, refer to the System Administration Guide.