Riskware policies allow you to identify files that are similar to malware, but that are not intended to be malicious. A file that is not a malicious threat might display behavior that affects threat detection, such as installing unwanted programs, modifying system settings, or reducing the overall performance of the appliance. Types of riskware include Potentially Unwanted Programs (PUPs), Potentially Unwanted Applications (PUAs), adware, and hacker tools.
To associate a riskware policy with a domain:
On the Domains page, select a domain.
Click the Manage link next to Riskware Rule Policy.
The subsequent screen displays the riskware rule policy, if any, associated with this domain or inherited from the domain group.
Click Change.
Select a policy, or None.
Click OK.
Click Save.
To create a new riskware policy, see Creating and deleting policies.

To manage a riskware policy:
Select a riskware policy.
Next to Rules, click Manage.
For each riskware rule you can select Disabled, Monitor, Alert, or Alert and Quarantine.
Monitor
Analyzes the email for riskware. Trellix Email Security — Cloud does not generate an alert or quarantine the email if the rule matches.
Alert
Analyzes the email and generates an alert if the rule matches.
Alert and quarantine
Analyzes the email, generates an alert, and moves the email to quarantine if the rule matches.
Disabled
Does not analyze emails for riskware.
Click Save.
The following table describes some of the riskware rules that can trigger a riskware alert. You can see the full list of riskware policy rules in the Web UI.
Riskware policy rule | Trigger condition |
|---|---|
65000 Jar Files Delivered Via Email Attachment Or Link | Jar files are delivered through email attachments or links. |
65001 Encrypted MS Office Document | Microsoft Office files in emails are encrypted. |
65002 PDF, HWP or MS Office Files With Network Activity Policy | Microsoft Office files are used for network activity. |
65003 Executable Delivered via Email Attachment or URL Link within Email Body | Email attachments have suspicious executable files (such as PEEXE or PEDLL). |
65004 Script Delivered via Email | Email messages include scripts. |
65007 MS Office Document With Embedded Object | Microsoft Office files have embedded objects. |
65008 MS Office Document With Macro Activity | Microsoft Office files have macro activity. |
65009 Non Executable file Connecting to Non-Standard High Port | Non-executable files that connect to ports above 1024. |
65010 MS Office Document with Network Activity and Embedded Object or Macro | Microsoft Office files have network activity and embedded objects or macros. |
65011 Uncommon File Types Delivered Via Email BAT, CPL, LNK, COM, CMD, MHT, PIF, PUB, HLP, HTA, ISO | Emails have file attachments with any of the following file types: BAT, CPL, LNK, COM, CMD, MHT, PIF, PUB, HLP, HTA, ISO |
65012 MS Office Document With Macro Activity Dropping a exe file | Microsoft Office files have macro activity that write executable files. |
65013 Password From Web Forms Found in Plaintext Http_Request | Email Web forms have passwords that are sent as plaintext HTTP requests. |
65016 Email with shortened link | Emails contain URLs that have been shortened. |
65017 Email with MS Access DB Attached | Email messages have Microsoft Access database attachments. |
65020 MS Office Document running Flash Events | MS Office files are running flash events. |
65021 MS Office Document With Password Protected Macro | MS Office files have password protected macros. |
65022 Login Page Sent as Email Attachment | Email messages send an attachment with a link to a login page. |
65023 Password Protected Zip .rar Archives | Email messages send attached password protected zip .rar archives |
65024 Uncommon Filetype Observed. Setting Content-ms Extension | Uncommon Filetype Observed. Setting Content-ms Extension |
65025 Suspicious File With Disagreeing Extension and MagicBytes | Email messages send suspicious file with disagreeing extension and magicbytes |
65027 High Confidence Email Impersonation | Email impersonation detection has determined that email impersonation is very likely. For more details see Impersonation Detection in Email Security - Server User Guide. |
65028 Low Confidence Email Impersonation | Email impersonation detection has determined that email impersonation is somewhat likely. For more details see Impersonation Detection in Email Security - Server User Guide. |
65029 Provided list of extensions marked for Policy Blocking | Provided list of extensions marked for policy blocking |
65030 Encrypted PDF Document | Email messages send an attachment with encrypted PDF document |
65031 Potential Risky ScreenSaver Indicator | Potential risky screensaver indicator |
65033 HTML Redirector Sent as Email Attachment | Email messages send an attachment with HTML code for redirection |
65034 Low Confidence Malware Guard on EX | Malware Guard scores a binary file as riskware rather than malware |
65035 Policy Low Confidence Malware Guard on NX/AX | Malware Guard scores a binary file as riskware rather than malware |
65036 Matching Recipient and Message ID Domains | An email message header has matching domains for recipient and message ID. |
65037 Suspicious DAA Archive Delivered via Email | Email messages have suspicious Direct Access Archive file attachments. |
65041 Attacker Abused Legit Tool | Detection of productivity or other legitimate tools that are known to be leveraged as threat actor tactics, techniques, and procedures (TTPs). |
65043 FireWall/AV Discovery via WMI | FireWall/AV discovery via WMI |
65044 Corrupt Windows PE File | Email messages send an attachment with corrupt Windows PE file |
65045 Office Document with Template Link | Email messages send an attachment with Office document with template link |
65046 MS Excel Formula Macro Sheet | Email messages send an attachment with MS Excel formula macro sheet |
65047 MS Office Document with Embedded SWF | Email messages send an attachment with MS Office document with embedded SWF |
65048 Policy MSIL Reflective Loader File thru Emails | Email messages send an attachment with MSIL reflective loader file |
65049 Policy File NSIS Delivered thru Emails | Email messages send an attachment with file NSIS |
65050 Policy File ONENOTE with Embedded Object Delivered thru Emails | Email messages send an attachment with file ONENOTE with embedded object |
65052 Potential ZipBomb | Potential zipbomb |
65053 Policy CryptoJS Used in JavaScript | CryptoJS used in JavaScript |
65054 Policy MS Excel Formula Python Script | MS Excel formula python script |
65055 Policy QR Code Observed | QR code observed |
65056 Policy JScript Deobfuscation Functions Observed | JScript deobfuscation functions observed |
65057 Policy Branchlock Obfuscated JAR File | Branchlock obfuscated JAR file |
65059 Policy Mitre Multiple Tactics Observed | Mitre multiple tactics observed |
65060 Policy RDP Files Delivered Via Email Attachment Or URL | RDP files delivered via email attachment or URL |
65061 Policy MSI File with Custom Action Scripts | Policy MSI File with Custom Action Scripts |
65062 Policy SVG File Delivered via Email | Policy SVG File Delivered via Email |
65063 Policy Password Protected HWP Document | Policy Password Protected HWP Document |
65064 Policy Packer Obfuscated MSIL | Policy Packer Obfuscated MSIL |
65065 Policy ClickOnce Deployment Manifest | Policy ClickOnce Deployment Manifest |
65066 Policy Password Extraction Failed | Policy Password Extraction Failed |
65067 Policy ClickOnce Deployment Manifest Process | Policy ClickOnce Deployment Manifest Process |
65068 Policy Double Extension FileName | Policy Double Extension FileName |
65069 Policy PDF Embedded Script | Policy PDF Embedded Script |
65070 Policy Theme File Delivered via Email | Policy Theme File Delivered via Email |
65071 Policy URLFeature CloudFlare Recaptcha Reasons | Policy URLFeature CloudFlare Recaptcha Reasons |
65072 Policy Document Files with Embedded URL | Policy Document Files with Embedded URL |