static-analysis av-suite enable

Prev Next

Enables Trellix's AV-Suite analysis tool. After the tool is enabled, no other configuration is required.

With AV-Suite integration, each infection binary is submitted by the appliance to the AV-Suite detection and comparison tool, which determines whether antivirus vendors were able to detect the malware that was captured and analyzed by FireEye. The results of AV-Suite analysis are displayed on the appliance Web UI results page.

AV-Suite analysis is enabled by default.

Note

AV-suite version 6 must be configured for AV-Suite to receive the suspicious object hashes through the DTI network to determine whether the object hashes have been seen before.

AV-Suite analysis is only available to customers using a 2-way license.

Syntax

[no] static-analysis av-suite enable

Parameters

no

Use the no form of this command to disable the AV-Suite integration tool.

Example

The following example enables AV-Suite integration.

hostname (config) # static-analysis av-suite enable

User role

Admin and Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Release 7.7.0. AV-suite version 6 must be configured for AV-Suite in Release 8.2.0.

  • File Protect: Release 7.7.0. AV-suite version 6 must be configured for AV-Suite in Release 8.2.0.

  • Network Security: Release 7.7.0. AV-suite version 6 must be configured for AV-Suite in Release 8.1.0.

  • Email Security — Server: Release 7.8.0. AV-suite version 6 must be configured for AV-Suite in Release 8.1.0.

  • Intelligent Virtual Execution - Server: Before Release 8.0. AV-suite version 6 must be configured for AV-Suite in Release 8.2.0.