You can also enable the option to extract and analyze objects, such as MSI, ZIP, RAR, 7Z, LZH, SWF, DLL, EXE, PDF, and Office files, that are embedded in other PDF, RTF, or Office files. If the embedded object is an executable, DLL, or MSI file, the parent container file is marked as malicious and is quarantined by the MVX. Analysis of the parent container file and the embedded file are performed separately, as if they are individual files; if one of the files is found to be malicious, eAlerts notification and an eQuarantine notification will be generated according to your configuration.
Embedded attachments
- Published on Aug 24, 2026
- 1 minute(s) read
Was this article helpful?
Related articles
- Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Configuring system components > Documenting events with evidence > Using evidence and evidence storage
- Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.14.x Product Guide > Configuring system components > Documenting events with evidence > Using evidence and evidence storage
- Email Security - Server > Email Security - Server User Guide Release 11.x > Configuration > System configuration > Static analysis tools > Embedded URL analysis > Enabling or disabling analysis of embedded URLs in files
- Email Security - Cloud > Email Security - Cloud Administration Guide Release 2026.2 > System configuration > Configuring policies