Configuring riskware file blocking using the Web UI

Prev Next

Follow these steps to globally enable or disable the blocking of files based on riskware detected by Trellix Riskware rules on the File Protect appliance.

Note

Riskware detection alerts are generated by default when files are blocked.

EX_RiskwareAdwareRulesEnableDisable_scap.png
To enable blocking files based on riskware detected by the Trellix Riskware rules:
  1. In the Web UI, choose Settings > Riskware Policy.

  2. Select the FireEye Riskware Rules tab.

  3. Click the Quarantine checkbox for the Trellix Riskware rules.

  4. Click Apply. The following message appears:

    Updated selected Riskware Rules.
To disable blocking files based on riskware detected by the Trellix Riskware rules:
  1. In the Web UI, choose Settings > Riskware Policy.

  2. Select the FireEye Riskware Rules tab.

  3. Clear the Quarantine checkbox for the TrellixRiskwarerules.

  4. Click Apply. The following message appears:

    Updated selected Riskware Rules.