Suspicious Object Scan Actions

Using the Apex Central console, administrators can configure scan actions that certain managed products take after detecting specific suspicious objects in the Virtual Analyzer Suspicious Objects list or the User-Defined Suspicious Objects list.

Important:

Apex Central does not support the "Quarantine" scan action. Selecting the "Quarantine" scan action for user-defined File SHA-1 objects will perform the "Block" scan action on detected objects.

Virtual Analyzer List

User-Defined List

Performs actions against the following suspicious object types:

  • File: Log, Block, Quarantine

  • IP address: Log, Block

  • URL: Log, Block

  • Domain: Log, Block

Performs actions against the following suspicious object types:

  • File: Log, Block, Quarantine

  • File SHA-1: Log, Block

  • IP address: Log, Block

  • URL: Log, Block

  • Domain: Log, Block