If Trellix does not have any data about the file, you can choose to automatically submit the file to your on-premises Trellix Malware Analysis, your Local IVX cluster for MVX analysis, and to your IVX Cloud subscription. A file acquisition is automatically triggered and submitted for analysis. After the analysis is complete, an operating system change report is generated, and the data from this report is added to the Endpoint Security message bus.
The Enricher Module also provides additional detection validation for Malware Protection, Malware Guard, Exploit Guard, and Real-Time Indicators. Files detected by those features can be automatically submitted to the Trellix Malware Analysis product and any other configured submission service.
To reduce data resubmission, the Enricher Module includes a local cache of previously collected MD5 data. If the MD5 is currently in the local cache, files with that MD5 will not be submitted to your additional data source options. The MD5 remains in the local cache for 30 days.