Malware alerts and notifications

Prev Next

When malware is detected on the host endpoint, a malware alert is also generated in the Web UI. Alerts generated by MalwareGuard have a unique subtype ("mg") to distinguish them from alerts detected by antivirus (subtype "av"). See the Endpoint Security (HX) Server User Guide for more information about viewing malware alerts in the Web UI.

Note

Endpoint Security (HX) xAgent version 27 or later supports MalwareGuard alerts.

Malware alerts do not trigger an automatic triage. You can manually create a triage from a malware alert to study an intrusion and use your third-party antivirus software to resolve malware alerts on your Windows or macOS host endpoint. You cannot collect triage data for Linux host endpoints. See "Triage Collections: in the Endpoint Security (HX) Server User Guide.

Alerts produced for malware are aged in the same manner as HX alerts for indicators of compromise (IOCs). See "Indicator and Alert Aging" in the Endpoint Security (HX) Server User Guide.

Notification alerts on the host endpoint

Endpoint Security (HX) xAgent version 26 or later supports Endpoint Security (HX) notification alerts on the host endpoint. This means when an infected file is quarantined or cleaned on a host endpoint in your enterprise, the affected endpoint receives a notification alert of the malware protection action. Endpoint Security (HX) also sends a notification alert to the host endpoint when the malware definitions are out of date. This notification alert prompts the local user to update the malware definitions on their host endpoint.

Note

Endpoint Security (HX) notification alerts are supported on host endpoints running in specific Windows environments only. They are not supported for host endpoints running Windows 2003, XP, and Vista.

Malware protection is not supported for host endpoints running Linux operating systems.

Trellix Endpoint Security (HX) notification alerts are disabled by default. Use policies to enable these notification alerts by modifying the xAgent default policy to configure Endpoint Security (HX) notification alerts for all of your host endpoints or create a custom policy to configure Endpoint Security (HX) notification alerts for specific host sets.

Endpoint Security (HX) xAgent version 26 supports internationalization for Trellix Endpoint Security (HX) notification alerts on the host endpoint. In Windows environments, notification alerts are translated into Chinese (simplified and traditional), French, German, Italian, Japanese, Korean, Polish, Portuguese Brazilian, Russian, and Spanish. The default language is English

The language translation will match your Windows UI language selection. For example, if the language selection for your Windows explorer.exe is Chinese, Trellix Endpoint Security (HX) notification alerts are translated into Chinese. If your Windows UI language selection does not match one of the supported languages, you will receive Trellix Endpoint Security (HX) notification alerts in English.