Complete the steps for managing riskware in the following order:
(Optional) Enable AV-Check on the File Protect appliance. For details about how to enable AV-Check, see Enabling or disabling AV-Check.
(Optional) Verify that AV-Suite integration is enabled on the File Protect appliance. Use the show static-analysis config command.
(Optional) Verify that the File Protect appliance is configured to perform YARA analysis. Use the show static-analysis config command.
(Optional) Trellix riskware detection is enabled on the appliance by default, but you can choose to disable and re-enable it. See Enabling or disabling riskware detection policy rules.
You can enable or disable specific Trellix riskware policy rules. See Enabling or disabling riskware detection policy rules.
View the results on the eAlerts > Riskware page in the Web UI. For details about how to view the riskware alerts in the Web UI, see Viewing riskware alert details in the Web UI.
You can enable or disable blocking emails based on riskware detected by Trellix Riskware. See Enabling or disabling blocking emails based on riskware detection custom policy rules.