MalwareGuard

Prev Next

The MalwareGuard feature is a new way of detecting malware using a machine learning model. It uses static analysis to detect malware, including ransomware and new malware variants, on execution in near real-time for portable executable (PE) files. (PE is a file format associated with exe, dll, sys, drv, mui, cpl, and scr files in both 32-bit and 64-bit versions of the Windows operating system.) Malware Protection now scans each file using both the Antivirus and MalwareGuard engines.

Important

Malware Protection must download and update intel on the host at least once before MalwareGuard can function. Once the initial intel is downloaded by the xAgent , the Antivirus option can then be disabled, and MalwareGuard will continue to function on the host. See Configuring the Malware Protection Indicator Download Channel for more on this configuration.

By default, MalwareGuard is in detect-only mode. If you want MalwareGuard to quarantine harmful files, you must enable quarantine actions in the Web UI or API. For more information about policies, see the Trellix Endpoint Security Agent (HX) Administration Guide.