Malware detection

Prev Next

Malware detection, which includes MalwareGuard, utilizes two scanning engines to guard and defend your host endpoints against malware infections, the Antivirus engine and the MalwareGuard engine.

  • Antivirus Engine (Signature and Heuristic Detection)—when you enable malware detection, the AV engine performs signature-based and heuristic-based scans on all files when they arrive on your endpoint. If malware is detected in a file, the scan is aborted. Protection actions are performed on the file, if quarantine is enabled.

  • MalwareGuard—when you enable MalwareGuard, files are submitted to the MalwareGuard engine for scanning. If malware is detected, the scan is aborted. Protection actions are performed on the file, if you have quarantine enabled for MalwareGuard.

MalwareGuard

The MalwareGuard feature detects malware using a machine learning model. Through static analysis and predictive analytics, MalwareGuard detects malware, including ransomware and new malware variants, on execute in near real-time for portable executable (PE) files. PE is a file format associated with exe, dll, sys, drv, mui, cpl, and scr files in both 32-bit and 64-bit versions of the Windows operating system.

Enabling malware detection on your host sets, allows the xAgent to scan files on your host endpoints using both the Antivirus and MalwareGuard engines. The Antivirus engine uses signature and heuristic detection to identify files that match malware definitions or characteristics of a known malware to identify malicious files, while, the MalwareGuard engine scans files using predictive models to identify malicious files.

You can enable MalwareGuard for any policy independently from Signature and Heuristic Detection.

By default, MalwareGuard is in detect-only mode. If you want MalwareGuard to quarantine harmful files, you must enable quarantine actions in the Web UI or API.

Note

MalwareGuard is supported in Trellix Endpoint Security (HX) xAgent version 27 or later only.