Malware protection has two components: malware detection and quarantine. Malware detection performs malware scanning of all files and applications on your host endpoints and uses malware definitions to detect and identify malware infections. When malware protection identifies a file for the first time, it initiates a full malware scan. Clean files are cached, and infected files, which cannot be cleaned, are quarantined. Malware protection will not scan a cached file unless the file is modified after the initial scan. Malware protection does not perform deferential malware scans. All modified files receive another full malware scan.
After files are scanned, quarantine allows you to isolate infected files so they cannot spread the malicious code to other files on your host endpoint or to other endpoints on your network. It also allows you to perform specific remediation actions on quarantined files.
You can configure malware detection to perform on-access malware scans on local files, on-access malware scans on network files, and on-demand scans on local files.
Note
Trellix Endpoint Security (HX) xAgent version 26 supports malware scanning on all files (up to 2 GB in size) on your host endpoints.
Malware detection is provided only for host endpoints running Endpoint Security (HX) xAgent version 24 or later. Malware protection is provided only for host endpoints running Endpoint Security (HX) xAgent version 26 or later.
This section covers the following topics: