Enables Trellix's AV-Suite analysis tool. After the tool is enabled, no other configuration is required.
With AV-Suite integration, each infection binary is submitted by the appliance to the AV-Suite detection and comparison tool, which determines whether antivirus vendors were able to detect the malware that was captured and analyzed by FireEye. The results of AV-Suite analysis are displayed on the appliance Web UI results page.
AV-Suite analysis is enabled by default.
Note
AV-suite version 6 must be configured for AV-Suite to receive the suspicious object hashes through the DTI network to determine whether the object hashes have been seen before.
AV-Suite analysis is only available to customers using a 2-way license.
Syntax
[no] static-analysis av-suite enable
Parameters
no
Use the no form of this command to disable the AV-Suite integration tool.
Example
The following example enables AV-Suite integration.
hostname (config) # static-analysis av-suite enable
User role
Admin and Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Malware Analysis: Release 7.7.0. AV-suite version 6 must be configured for AV-Suite in Release 8.2.0.
File Protect: Release 7.7.0. AV-suite version 6 must be configured for AV-Suite in Release 8.2.0.
Network Security: Release 7.7.0. AV-suite version 6 must be configured for AV-Suite in Release 8.1.0.
Email Security — Server: Release 7.8.0. AV-suite version 6 must be configured for AV-Suite in Release 8.1.0.
Intelligent Virtual Execution - Server: Before Release 8.0. AV-suite version 6 must be configured for AV-Suite in Release 8.2.0.