Riskware

Prev Next

Riskware detection allows you to identify files that are similar to malware but are not intended to be malicious. A file that is not a threat might display behavior that affects threat detection, such as installing unwanted programs, modifying system settings, or reducing the overall performance of the appliance. Types of riskware include Potentially Unwanted Programs (PUPs), Potentially Unwanted Applications (PUAs), adware, and hacker tools. This feature allows you to easily distinguish between malicious files and riskware on the File Protect appliance. You can configure optional riskware detection so that the Multi-Vector Virtual Execution (MVX) engine does not mark the riskware files as malicious, and the files will be excluded from further analysis. The submission status for a riskware alert is marked as Riskware in the output of the show submission id command.

The riskware detection feature is enabled by default on the appliance. You can choose to disable the Trellix riskware rules and enable a single or multiple custom riskware policy rules using the Web UI or CLI. When you enable at least one matched policy rule on the File Protect appliance, you can choose to have the appliance either generate a riskware alert on a non-malicious submission or block an email from being delivered to the intended recipient.

The File Protect appliance can also alert or block files that have a certain file extension. For details about riskware detection custom policy configuration, see Configuring Riskware Detection custom policy rules for file extensions.

Note

You can view retroactive riskware alerts from the What's Happening panel of the File Protect dashboard when you click Riskware Alerts, but retroactive riskware can not be viewed when you click Retroactive Alerts.

This section covers the following information about configuring riskware analysis: