The File Protect platform scans network file shares to detect and quarantine malware. File scans can be performed at any time (on-demand), or scheduled to run continuously, daily, or weekly. Preliminary scans allow you to gather initial statistics about a share, which you can use to adjust scan criteria before you schedule or start the scan.
Scan results provide details about the status and outcome of scans. Analysis results provide detailed MVX engine observations about malware behavior and operating system changes that were detected during deep analysis of the file object. With full integration with the CM Series platform, the threat indicators are shared with other Trellix products for immediate action. Additionally, CnC callback events detected by the MVX engine can be sent to the File Protect platform for additional forensic analysis.
Filters allow you to tailor scans so they provide the right amount of coverage without overloading the system. You can filter scans by file type, location, modification date, and so on. For example, a scan could analyze only .doc and .exe files in the Training directory that were changed or added within the last two weeks. You can also define specific file types to whitelist when they are encountered.
Shares with the Files share type will be scanned; shares with the Quarantine and Good/Whitelist/Unknown share types will not be scanned. If configured, the appliance will move malicious files to a Quarantine share when they are encountered. This isolates malware from network assets, reducing its potential to cause harm to the file system in use. If a Good/Whitelist/Unknown share is configured, non-malicious, whitelisted, and unknown files can be moved to that share to reduce the amount of time and resources used by the next scan.
If your forensic analysis determines that a quarantined file is safe, you can release it from quarantine, which returns the original file to its original location on the share and puts it on an internal whitelist. You can also delete a malicious file permanently. If you believe the event that caused the file to be marked malicious is a false positive, you can suppress it so it will not be marked malicious the next time files with matching MD5 checksums are analyzed.
File Protect alerts are retained in the appliance database until event and malware record thresholds are reached. These thresholds specify the number of event and malware records that can be stored in the appliance database. They are set using the fedb events archival himark and fedb malware archival himark CLI commands. For most appliances, the defaults are 500,000 event records and two million malware records. For 10G appliances, the defaults are two million event records and eight million malware records. See the CLI Reference Guide for more information about these commands.