The Trellix File Protect appliance analyzes file shares using the patented Trellix Multi-Vector Virtual Execution (MVX) engine that detects zero-day malicious code embedded in common file types. The File Protect appliance performs recursive, scheduled, and on-demand scanning of accessible network file shares to identify and quarantine resident malware, without impact to corporate productivity.
File Protect appliance file share access
The File Protect appliance accesses network file shares remotely, so deployment of the File Protect appliance is not specific to a network location. The File Protect appliance deployment requires only that the appliance has remote access to the enterprise network from the Trellix management network, has access to any directory in the enterprise network, and can mount a directory share in the enterprise file system.
Note
Trellix recommends that the File Protect appliance be located near large file shares.
The File Protect appliance uses the network gateway to the file system, so network share access must be resolvable through the Default Gateway address you specify on the Network Settings page when setting up the appliance. See Basic network configuration .
Note
All Trellix appliances use the network port ether1 for management connectivity. The management port is never bridged directly to the MVX engines for analysis.
File Protect workflow
Use the following workflow to configure and perform network share malware analysis.
After installing the File Protect appliance and providing Trellix with network share access to all directories in the enterprise that will be proactively scanned, use the File Protect Web UI Settings pages to configure the appliance’s network settings and licenses. Configuration requires Trellix DTI access or the use of the DTI Offline Update Portal.
Configure email settings, scan results notifications, and other appliance settings and requirements.
Note
All File Protect functionality is fully configurable and operable from the Central Management System appliance. If the File Protect appliance is being managed by the Central Management System appliance, Trellix recommends that you perform the File Protect configuration from the Central Management System appliance, not from the File Protect appliance.
Mount CIFS, NFS, WebDAV, or Secure WebDAV network share(s) from the Storage > Add Storage > Configure Storage tab to configure File Protect remote access to all directories in the enterprise.
Click Configure a Scan for immediate file share malware analysis, or define a scan schedule.
(Optional) Use the Storage > Add Storage > Configure Storage tab to configure a remote quarantine if you plan to isolate malicious files; quarantined files require read/write access from the network share.
Quarantine share name and URL are referenced in network share configurations.
Use the Scans > Configure a Scan tab to schedule periodic or continuous network share scanning.
Use the Scans tab to view detailed information about scans and analysis results.
Filter scan results to view results from various time periods, and click the Results buttons to drill down deeply into more detailed information about detected resting malware.
View quarantine and quarantined file information from the Scans > Quarantined Files tab.
Click Print PDF at each expandable level to generate a scan analysis report for that page.
Use the Reports tab to generate executive and individual network share malware analysis reports for forensic analysis.
Use the Update options under the About tab to upgrade software, install security content and software patches, and exchange appliance encryption keys.
Use the Dashboard to view summary information for recently scheduled and ad hoc scans.