Enables or disables riskware detection on the appliance.
The riskware detection feature allows you to identify files that are similar to malware but are not intended to be malicious. A file that is not a threat might display behavior that affects threat detection, such as installing unwanted programs, modifying system settings, or reducing the overall performance of the appliance. Types of riskware include Potentially Unwanted Programs (PUPs), Potentially Unwanted Applications (PUAs), adware, and hacker tools. This feature allows you to easily distinguish between malicious files and riskware on the appliance. You can configure optional riskware detection so that the Multi-Vector Virtual Execution (MVX) engine does not mark the riskware files as malicious, and the files will be excluded from further analysis. The submission status for a riskware alert is marked as Riskware in the output of the show submission id command.
When riskware detection is enabled on the appliance, you can also enable riskware detection custom policy rules. When you enable at least one matched policy rule on the EX Series appliance, you can choose to have the EX Series appliance either generate a riskware alert on a nonmalicious submission or block an email from being delivered to the intended recipient. When you enable at least one matched policy rule on the Network Security appliance, you can have the Network Security appliance generate a riskware alert on a nonmalicious submission.
The riskware detection feature is disabled by default.
Syntax
[no] analysis riskware enable
Parameters
no
Use the no form of this command to disable riskware detection.
Example
The following example enables riskware detection on the appliance:
hostname (config) # analysis riskware enable
The following example disables riskware detection on the appliance:
hostname (config) # no analysis riskware enable
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 8.0. Deprecated in Release 8.4.1.
Network Security: Release 8.0. Deprecated in Release 8.4.1.