Enabling or disabling Trellix Riskware detection using the Web UI

Prev Next

Use the Riskware Policy Settings page to globally enable or disable Trellix Riskware detection on the File Protect appliance.

EX_RiskwareAdwareRulesEnableDisable_scap.png
To enable the Trellix Riskware rules for alerts:
  1. In the Web UI, choose Settings > Riskware Policy.

  2. Select the FireEye Riskware Rules tab.

  3. Click the Alert Only checkbox for FireEye Riskware to enable riskware alerts.

  4. Click Apply.

  5. Click Yes to confirm.

  6. Verify the status. The FireEye Riskware (Adware/PUP/Spam) rule will have Enabled in the Alert Only column.

    hostname (config) # show analysis riskware policy rules
    |------------|-----------------------------------------------------------|------------|------------|
    |    Rule ID |                                                      Rule | Alert Only | Quarantine |
    |------------|-----------------------------------------------------------|------------|------------|
    |      65000 |          Jar Files Delivered Via Email Attachment Or Link |   Disabled |   Disabled |
    |      65001 |                              Encrypted MS Office Document |   Disabled |   Disabled |
    |      65002 |         PDF, HWP or MS Office Files With Network Activity |   Disabled |   Disabled |
    .
    .
    .
    |      65037 |                Suspicious DAA Archive Delivered via Email |   Disabled |   Disabled |
    |      65038 |                         Supply Chain Impersonation (8.4x) |   Disabled |   Disabled |
    |            |                        FireEye Riskware (Adware/PUP/Spam) |    Enabled |   Disabled |
    |____________|___________________________________________________________|____________|____________|
    			
To disable the Trellix Riskware rules for alerts:
  1. Select the FireEye Riskware Rules tab.

  2. Clear the Alert Only checkbox for FireEye Riskware to turn off riskware alerts. By default, the quarantine checkbox also is cleared.

  3. Click Apply. The following message appears:

    A confirmation message recommends that you do not disable the set of Trellix Riskware rules.
  4. Click Yes to confirm.