On standalone Email Security - Server appliances, you will see a message on the Dashboard asking if you want to improve detection of malware.Trellix recommends using improved detection. Contact yourTrellix sales representative for more information.

If your Email Security - Server appliance is connected to a Central Management System platform, this feature is controlled from the Central Management System platform on the Appliance Settings page, and you will not see the Dashboard message on the Email Security - Server appliance.
Note
Improved Detection cannot be configured from the CLI.
Configuring improved detection using the Web UI
Suspicious Metadata
If you check the Suspicious metadata option, then metadata flagged by your appliance as "likely suspicious" will be sent toTrellix for analysis. This may result in more false positives being sent toTrellix for analysis, but will also increase detection rates for actual malware.
If you do not select this option, then only metadata flagged as "malicious" will be sent to FireEye.
Suspicious Files
Without checking this option,Trellix will receive only files that are reported as malicious by yourTrellix appliance. You may also choose to send suspicious files, that is, files that yourTrellix appliance flags as "likely malicious." This may result in more false positives being sent toTrellix for analysis, but will also increase detection rates for actual malware.
