You can enable and disable malware detection for all of your host sets using the xAgent default policy or for specific host sets in your environment using a custom policy. When malware detection is disabled, other malware protection policy settings are ignored. MalwareGuard is not disabled when malware detection is disabled.
Endpoint Security (HX) xAgent can run the MalwareGuard Engine independently of the Malware Protection Engine. When MalwareGuard only is turned on, any action on the Endpoint gets Malware scanning without depending on Anti-Virus protection. If both the MalwareGuard Engine and Malware Protection Engine are turned on, the Malware Protection Engine runs first.
When you enable malware detection, the latest malware definitions, which include protection indicators, are automatically downloaded to your agents.
Important
By default, the initial download of the malware definitions can take up to four hours to complete. Malware detection will not start until the malware definitions have been downloaded.
.png)
Trellix Endpoint Security (HX) xAgent version 26 and later supports malware scanning on all files (up to 2GB in size) on your host endpoints.
If you do not see any malware detected on your host endpoints, verify that any third-party antivirus software you have installed on your host endpoints is not preventing the Trellix Endpoint Security (HX) xAgent from functioning. See Excluding Agent Files in Your Antivirus Software.
This section covers how to use the Web UI to enable and disable malware detection. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your malware protection policies.
Enabling Malware Detection for All Host Endpoints
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Malware Protection tab.
In the Malware Detection section, toggle the Signature and Heuristic Detection ON/OFF switch to ON.
.png)
Click Save.
Enabling Malware Detection for Selected Host Sets
To enable malware detection for selected host sets:
Note
NOTE: See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Malware Protection tab.
In the Malware Detection section, toggle the Signature and Heuristic Detection ON/OFF switch to ON.
.png)
For Windows host sets, select the Cloud Lookup option if you want to enable cloud lookup.
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.
Disabling Malware Detection for Selected Host Sets
To disable malware detection for selected host sets.
Note
Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Malware Protection tab.
In the Malware Detection section, toggle the Signature and Heuristic Detection ON/OFF switch to OFF.
.png)
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.
Disabling Malware Detection for All Host Endpoints
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Malware Protection tab.
In the Malware Detection section, toggle the Signature and Heuristic Detection ON/OFF switch to OFF.
.png)
Click Save.