Understanding Malware Protection

Prev Next

Malware protection has two components: malware detection and quarantine. Malware detection performs malware scanning of all files and applications on your host endpoints and uses malware definitions to detect and identify malware infections. When malware protection identifies a file for the first time, it initiates a full malware scan. Clean files are cached and infected files, which cannot be cleaned, are quarantined. Malware protection will not scan a cached file unless the file is modified after the initial scan. Malware protection does not perform deferential malware scans. All modified files receive another full malware scan.

After files are scanned, quarantine allows you to isolate infected files so they cannot spread the malicious code to other files on your host endpoint or to other endpoints on your network. It also allows you to perform specific remediation actions on quarantined files.

You can configure malware detection to perform on-access malware scans on local files, on-access malware scans on network files, and on-demand scans on local files.

Note

Trellix Endpoint Security (HX) xAgent version 26 supports malware scanning on all files (up to 2 GB in size) on your host endpoints.

Malware detection is provided only for host endpoints running Endpoint Security (HX) xAgent version 24 or later. Malware protection is provided only for host endpoints running Endpoint Security (HX) xAgent version 26 or later.

This section covers the following topics:

Malware detection

Malware detection, which includes MalwareGuard, utilizes two scanning engines to guard and defend your host endpoints against malware infections, the Antivirus engine and the MalwareGuard engine.

  • Antivirus Engine (Signature and Heuristic Detection)—when you enable malware detection, the AV engine performs signature-based and heuristic-based scans on all files when they arrive on your endpoint. If malware is detected in a file, the scan is aborted. Protection actions are performed on the file, if quarantine is enabled.

  • MalwareGuard—when you enable MalwareGuard, files are submitted to the MalwareGuard engine for scanning. If malware is detected, the scan is aborted. Protection actions are performed on the file, if you have quarantine enabled for MalwareGuard.

MalwareGuard

The MalwareGuard feature detects malware using a machine learning model. Through static analysis and predictive analytics, MalwareGuard detects malware, including ransomware and new malware variants, on execute in near real-time for portable executable (PE) files. PE is a file format associated with exe, dll, sys, drv, mui, cpl, and scr files in both 32-bit and 64-bit versions of the Windows operating system.

Enabling malware detection on your host sets, allows the xAgent to scan files on your host endpoints using both the Antivirus and MalwareGuard engines. The Antivirus engine uses signature and heuristic detection to identify files that match malware definitions or characteristics of a known malware to identify malicious files, while, the MalwareGuard engine scans files using predictive models to identify malicious files.

You can enable MalwareGuard for any policy independently from Signature and Heuristic Detection.

By default, MalwareGuard is in detect-only mode. If you want MalwareGuard to quarantine harmful files, you must enable quarantine actions in the Web UI or API.

Note

MalwareGuard is supported in Trellix Endpoint Security (HX) xAgent version 27 or later only.

Malware definitions

Malware Protection uses malware definitions to detect and identify files infected by malware. You can download malware definitions from the Endpoint Security server or from a custom content server. You cannot download malware definitions from Trellix 's Dynamic Threat Intelligence (DTI) cloud.

On-Access malware scans

On-access malware scans occur when:

  • Files are created. These include files that are downloaded from an Internet browser, new files created on the host by any process, files extracted from archives, and files created by a copy and paste action.

  • Files are executed (a process is launched).

  • Files are opened. These include existing files opened from Windows Explorer, from media such as a USB or CD/DVD drive, and from network folders.

You can also configure malware protection to perform on-access malware scans of network files. These configuration settings allow you to manage how malware detection performs malware scanning for files accessed over your network. Scanning options include performing malware scans on file read-only operations, file write-only operations, or on file read and write operations. See Enabling and Disabling On-Access Network Scans for more information.

Note

On-access malware scans are not supported on Linux hosts.

On-Demand Malware Scans

Configure on-demand malware scans for your host endpoints by creating scheduled scans.

Important

If malware detection is disabled, on-demand malware scans are automatically disabled.

The following on-demand scan types are available through the Endpoint Security (HX) Web UI:

  • Time-based global malware scans occur daily, weekly, or monthly, based on your configuration settings.

  • Event-based global malware scans occur when malware signatures are updated or when the host endpoint boots or reboots.

  • Time-based exception malware scans occur daily, weekly, or monthly, for selected host sets in your enterprise. Host sets that apply this scheduled scan exception policy are excluded from the global scheduled scans.

  • Event-based exception malware scans occur for selected host sets in your enterprise when updates to malware signatures occur or when the host endpoint boots or reboots. Host sets that apply this scheduled scan exception policy are excluded from the global scheduled scans.

See Managing On-Demand Malware Scans for more information.

Quarantine and Remediation

Quarantine allows you to isolate infected files so they cannot spread the malicious code to other files or applications on your host endpoint or to other endpoints on your network. It also allows you to perform specific remediation actions after the file is placed in quarantine.

When you enable quarantine, infected files are moved from their original location on the host endpoint to a quarantine location on the host endpoint. After the file is relocated, you can perform additional remediation actions using the Web UI:

  • Clean infected files and remove malware traces. See Cleaning Quarantined Files and Removing Malware Traces from Quarantined Files for more information.

  • Send notification alerts to the host endpoint after an infected file is quarantined or cleaned. See Managing Malware Protection Notification Alerts for more information.

  • View quarantined files in the Web UI. See "Viewing Quarantined Files" in the Endpoint Security (HX) Server User Guide for more information.

  • Acquire quarantined files from the quarantine location. See "Acquiring Quarantined Files" in the Endpoint Security (HX) Server User Guide for more information.

  • Delete quarantined files from the quarantine location. See "Deleting Quarantined Files" in the Endpoint Security (HX) Server User Guide for more information.

  • Restore cleaned files to the original location on the host endpoint or an alternate location using the Web UI or the API. See "Restoring Quarantined Files" in the Endpoint Security (HX) Server User Guide or the Endpoint Security (HX) REST API Guide for more information.

Important

If malware detection is disabled, quarantine and remediation are automatically disabled.

Note

If malware protection notification alerts are enable on your host endpoint, alerts will display on the host endpoint when an infected file is quarantined or cleaned. See Endpoint Security (HX) Server User Guide and the Working with Trellix Endpoint Security notification alerts for more information.

Malware protection default settings

By default, malware protection is disabled in the xAgent default policy, which is automatically assigned to all host endpoints in your environment. This means malware detection, quarantine, and remediation are disabled by default. Toggle the Signature and Heuristic Detection ON and OFF switch, the MalwareGuard ON and OFF switch, and the Quarantine switch ON and OFF to enable and disable malware protection completely. See Enabling and Disabling Malware Detection, Managing File Quarantine, and Managing File Remediation for more information.

Malware protection policies

Your malware protection policies control which malware protection processes run on your host endpoints. The xAgent default policy defines the malware protection default settings and exclusions that apply to all of your host endpoints. You can create a custom policy to manage malware protection exclusions for select host sets in your environment, including the following:

  • Include or exclude network files from malware scanning.

  • Include or exclude specific host sets from malware scanning.

  • Include or exclude specific host sets from MalwareGuard.

  • Include or exclude specific host sets from file quarantine.

  • Include or exclude quarantined files from specific remediation actions, including file cleaning, trace removal, and notification alerts.

  • Include or exclude specific processes, files and folders, and MD5 hashes from real-time malware scanning.

The following table summarizes the malware protection policy settings.

Policy Setting

Description

Reference

Malware Detection

Enable and disable Signature and Heuristic Detection for all of your host endpoints or select host sets in your environment.

See Enabling and Disabling Malware Detection.

Cloud Lookup

If Malware Detection is enabled, you can enable or disable cloud lookup for Windows hosts.

MalwareGuard

Enable and disable

Malware Detection Options

Enable and disable on-access malware scans of network files on all of your host endpoints or select host sets in your environment.

See Enabling and Disabling On-Access Network Scans.

Malware Definitions Updates

Define the download source and the update frequency for malware definition updates received by all of your host endpoints or select host sets in your environment.

See Configuring the Update Interval for Malware Protection Indicators and Configuring the Malware Protection Indicator Download Channel.

Quarantine

Enable and disable file quarantine and remediation for all of your host endpoints or select host sets in your environment.

See Managing File Quarantine.

Remediation Actions

Enable and disable file remediation actions for all of your host endpoints or select host sets in your environment.

See Managing File Remediation.

Remediation Actions for MalwareGuard

Enable and disable file remediation actions for MalwareGuard processing for all of your host endpoints or select host sets in your environment.

See Managing Remediation Actions for MalwareGuard.

Policy Exclusions

Exclude specific processes from malware protection processing, including malware detection, quarantine, and remediation, for all hosts in the enterprise.

See Excluding Processes from Malware Protection.

Exclude specific files and folders from malware protection processing, including malware detection, quarantine, and remediation, for all hosts in the enterprise.

See Excluding Files and Folders from Malware Protection.

Exclude specific MD5 hashes from malware protection processing, including malware detection, quarantine, and remediation, for all hosts in the enterprise.

See Excluding MD5 Hashes from Malware Protection.

Note

Excluding host sets, processes, files and folders, or MD5 hashes from malware protection processing is not recommended because it restricts the items that malware protection scans.

See Reviewing Malware Protection Policy Settings to review the current settings.

Malware alerts and notifications

When malware is detected on the host endpoint, a malware alert is also generated in the Web UI. Alerts generated by MalwareGuard have a unique subtype ("mg") to distinguish them from alerts detected by antivirus (subtype "av"). See the Endpoint Security (HX) Server User Guide for more information about viewing malware alerts in the Web UI.

Note

Endpoint Security (HX) xAgent version 27 or later supports MalwareGuard alerts.

Malware alerts do not trigger an automatic triage. You can manually create a triage from a malware alert to study an intrusion and use your third-party antivirus software to resolve malware alerts on your Windows or macOS host endpoint. You cannot collect triage data for Linux host endpoints. See "Triage Collections: in the Endpoint Security (HX) Server User Guide.

Alerts produced for malware are aged in the same manner as HX alerts for indicators of compromise (IOCs). See "Indicator and Alert Aging" in the Endpoint Security (HX) Server User Guide.

Notification alerts on the host endpoint

Endpoint Security (HX) xAgent version 26 or later supports Endpoint Security (HX) notification alerts on the host endpoint. This means when an infected file is quarantined or cleaned on a host endpoint in your enterprise, the affected endpoint receives a notification alert of the malware protection action. Endpoint Security (HX) also sends a notification alert to the host endpoint when the malware definitions are out of date. This notification alert prompts the local user to update the malware definitions on their host endpoint.

Note

Endpoint Security (HX) notification alerts are supported on host endpoints running in specific Windows environments only. They are not supported for host endpoints running Windows 2003, XP, and Vista.

Malware protection is not supported for host endpoints running Linux operating systems.

Trellix Endpoint Security (HX) notification alerts are disabled by default. Use policies to enable these notification alerts by modifying the xAgent default policy to configure Endpoint Security (HX) notification alerts for all of your host endpoints or create a custom policy to configure Endpoint Security (HX) notification alerts for specific host sets.

Endpoint Security (HX) xAgent version 26 supports internationalization for Trellix Endpoint Security (HX) notification alerts on the host endpoint. In Windows environments, notification alerts are translated into Chinese (simplified and traditional), French, German, Italian, Japanese, Korean, Polish, Portuguese Brazilian, Russian, and Spanish. The default language is English

The language translation will match your Windows UI language selection. For example, if the language selection for your Windows explorer.exe is Chinese, Trellix Endpoint Security (HX) notification alerts are translated into Chinese. If your Windows UI language selection does not match one of the supported languages, you will receive Trellix Endpoint Security (HX) notification alerts in English.

xAgent log

The xAgent log allows you to audit malware protection processing by providing scan messages for on-access and on-demand malware scans performed on endpoints in your enterprise. Each scan message includes the following information:

  • Scan start time

  • Scan completion status

  • Cause for incomplete malware scans (Example: a reboot or an error, which caused an incomplete scan.)

  • Scan duration

  • Number of files scanned

  • Number of detections identified

  • Scan type (Full, quick, or active-memory)

When you request xAgent Diagnostics for a host endpoint in the Web UI, the xAgent log is included in the output. You can also extract the log from the xAgent on your host endpoint. See Auditing Malware Scans in the Agent Log for more information.

Third-Party antivirus software considerations

Trellix strongly recommends that you create a custom policy in the Web UI that excludes processes and files and folders for any third-party antivirus software installed on your host endpoints, including the following:

These exclusions will maximize performance, ensure compatibility with other antivirus software, and reduce the number of duplicate alerts you receive from the malware protection feature and your third-party antivirus software. Use the xAgent default policy to define global malware protection exclusions. See Defining the Malware Protection Exclusion Policy for more information.

Important

Malware protection process, file and folder, or MD5 hash exclusions defined in the xAgent default policy do not apply to host sets assigned to a custom policy, if the custom policy defines different malware protection policy settings. To exclude processes and files and folders for third-party antivirus software installed on your host endpoints, you must define these exclusions for all policies that include a malware protection policy.

In addition, be sure to whitelist the Endpoint Security (HX) xAgent files in your third-party antivirus software, as described in Excluding Agent Files in Your Antivirus Software.

For example, if you are running Symantec Endpoint Protection (SEP), you should create exclusions in SEP for Trellix Endpoint Security (HX) xAgent processes, files, and folders. In addition, you should create exclusions for SEP processes, files, and folders in the xAgent default policy.

Windows security center integration

Trellix Endpoint Security (HX) xAgent version 27 and later integrates with Windows Security Center. This means that Trellix Endpoint Security (HX) is a certified and supported antivirus and antispyware product on specific Windows operating systems. See "Operating System Requirements" in the Endpoint Security Agent (HX) Deployment Guide for more information about the supported Windows versions.

When you enable malware protection processing, including malware detection, malware scanning, and file quarantine on your host endpoint, Trellix Endpoint Security (HX) registers with the Windows Security Center on your host endpoint.

Note

Windows Defender is the default antivirus program for endpoints running Windows 10. On Windows Desktop OSs, Windows Defender is automatically disabled when you enable the malware protection feature on your host endpoints

On Windows Server OSs, if Windows Defender is enabled, Trellix Malware Protection and Windows Defender will run simultaneously. This could cause performance issues and unpredictable behavior. An administrator can uninstall Windows Defender, disable it by using a Group Policy setting, or set Defender to "Passive mode" (for Server 2019). If you want to run both Windows Defender and Trellix Malware Protection, Trellix recommends that you have the two agents exclude each other.

You can view details about Trellix Endpoint Security (HX) on your host endpoint in the Windows Action Center. Any third-party antivirus software running on your host endpoint will also appear in the Windows Action Center.

When malware protection processing is enabled, the Actions Center displays the following information:

  • Virus protection—Indicates Trellix Endpoint Security is up-to-date and malware scanning is enabled.

  • Spyware and unwanted software protection—Indicates Trellix Endpoint Security (HX) is turned on.

When you disable malware protection on your host endpoint, the Windows Action Center displays a message to indicate Trellix Endpoint Security (HX) is turned off. See Enabling and Disabling Malware Detection and Managing File Quarantine for instructions on how to enable malware protection processing.

Note

Only Endpoint Security (HX) server administrators are authorized to enable or disable malware protection using the Web UI or the API. The Trellix Endpoint Security (HX) Turn on now button in the Windows Action Center is not functional. This prevents unauthorized users from enabling and disabling malware protection.

Endpoint Security (HX) xAgent and ELAM compatibility

To register with the Windows Security Center (WSC) as a supported anti-malware product, third-party anti-malware products running on Windows 10 Redstone 5 or later must be Microsoft ELAM (Early Launch AntiMalware) compatible. Trellix Endpoint Security (HX) xAgent version 29.7.8 and later meets this compatibility requirement.

When you install the Endpoint Security (HX) xAgent version 29.7.8 or later on your Windows endpoint running Windows 10 Redstone 5 or later, the ELAM driver is also installed on your Windows host. The ELAM driver stores certificate information that allows the agent to launch and run on your Windows endpoint as a protected service.