About Advanced URL Defense

Prev Next

The Advanced URL Defense feature allows you to identify suspicious URLs that are embedded in documents downloaded from the Internet.

When the Intelligent Virtual Execution - Server appliance identifies a suspicious URL within a document, it redirects the URL to the Dynamic Threat Intelligence (DTI) Cloud for a complete analysis. If the suspicious URL is found to be malicious, a web-infection alert is generated.

Task list for managing Advanced URL Defense

Complete the steps for managing Advanced URL Defense in the following order:

  1. Log in to the CLI to specify the settings for Advanced URL Defense.

  2. Verify that the Faude service address is set to unity.fireeye.com using the show fenet dti configuration command. For details about how to set the DTI server address for Faude, refer to the Network Security System Administration Guide.

    Important

    By default, this address for managed appliances is the address of the managing Central Management System appliance. For more effective detection and remediation, Trellix recommends a direct connection to unity.fireeye.com.

  3. Enable Advanced URL Defense. For details, see Enabling or disabling Advanced URL Defense

  4. View the statistics for the total number of URLs that have been sent to the DTI Cloud for analysis. For details, see Viewing the statistics for the URLs .

  5. Track the infected URLs that are related to Advanced URL Defense by using the Alerts Summary widget in the dashboard.