malwareDetection Section Settings

Prev Next

The malwareDetection settings provide keys that define how malware protection is configured, including malware detection processing and quarantine actions.

Select a setting from the table below to determine the edit method Trellix supports. Some of the settings listed in this table can also be changed manually for an individual host by modifying the agent configuration file.

Setting Key

Default

Supported Edit Methods

Web UI

CLI

API

clean32_uri

Set by the Endpoint Security server.

No

No

No

clean64_uri

Set by the Endpoint Security (HX) server.

No

No

No

enable

false

Yes

Yes

Yes

excludedFiles

---

Yes

Yes

Yes

excludedMD5s

---

Yes

Yes

Yes

excludedProcesses

---

Yes

Yes

Yes

network_oas

See malwareDetection network_oas Section Settings for setting keys and default values.

Yes

Yes

Yes

quarantine

See malwareDetection quarantine Section Settings for setting keys and default values.

Yes

Yes

Yes

update_enabled

false

No

No

No

update_interval

14400 seconds (4 hours)

Yes

Yes

Yes

update_source

Internet

Yes

Yes

Yes

update_url32

http://avupdate.fireeye.com/av32bit

No

No

No

update_url64

http://avupdate.fireeye.com/av64bit

No

No

No