You can enable or disable riskware detection policy rules by using the Email Security - Server appliance Web UI or CLI:
When you enable a particular policy rule based on riskware detection on the appliance, traffic matching the submission is marked as custom riskware and it will be excluded from further analysis. When you disable a particular policy rule based on riskware detection, traffic matching the submission is not marked as custom riskware. After you have configured the Email Security - Server appliance to detect a riskware policy rule, you can view the analysis results on the eAlerts > Riskware page in the Web UI. For details about how to view the matched riskware alerts, see Viewing riskware alert details in the Web UI.
Prerequisites
Administrator or Operator access to the Email Security - Server appliance
An established connection to the Internet
A connection to the DTI Cloud
Download and install the latest security content with new riskware policy rules by using the
fenet security-content apply-updatecommand, For details about how to update security content, refer to the System Administration Guide.