You can enable and disable malware detection for all of your host sets using the xAgent default policy or for specific host sets in your environment using a custom policy. When malware detection is disabled, other malware protection policy settings are ignored. MalwareGuard is not disabled when malware detection is disabled.
Endpoint Security (HX) xAgent can run the MalwareGuard Engine independently of the Malware Protection Engine. When MalwareGuard only is turned on, any action on the Endpoint gets Malware scanning without depending on Anti-Virus protection. If both the MalwareGuard Engine and Malware Protection Engine are turned on, the Malware Protection Engine runs first.
When you enable malware detection, the latest malware definitions, which include protection indicators, are automatically downloaded to your agents.
Important
By default, the initial download of the malware definitions can take up to four hours to complete. Malware detection will not start until the malware definitions have been downloaded.
.png)
Trellix Endpoint Security (HX) xAgent version 26 and later supports malware scanning on all files (up to 2GB in size) on your host endpoints.
If you do not see any malware detected on your host endpoints, verify that any third-party antivirus software you have installed on your host endpoints is not preventing the Trellix Endpoint Security (HX) xAgent from functioning. See Excluding Agent Files in Your Antivirus Software.
This section covers how to use the Web UI to enable and disable malware detection. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your malware protection policies.