You can enable or disable blocking files based on riskware detected by Trellix Riskware rules by using the File Protect appliance Web UI or CLI:
When you enable riskware detection both to generate a riskware alert and to block a file, the File Protect appliance blocks files that might be suspicious. In this scenario, a malware object event notification is generated if the sample is detected as riskware. You can view the analysis results on the eAlerts > Alerts page in the Web UI.
Note
Blocking files based on the riskware detection feature is disabled by default.
Prerequisites
Administrator or Operator access to the File Protect appliance
An established connection to the Internet
A connection to the DTI Cloud
Download and install the latest security content with new riskware policy rules by using the
fenet security-content apply-updatecommand, For details about how to update security content, refer to the System Administration Guide.