MCAFEE-MWG-MIB :: stMalwareDetected

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsMCAFEE-MWG-MIBstMalwareDetected

stMalwareDetected

Module: MCAFEE-MWG-MIB

OID (symbolic): MCAFEE-MWG-MIB::stMalwareDetected

OID (numeric): 1.3.6.1.4.1.1230.2.7.2.1.2

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: Number of infections detected by the McAfee Gateway Antimalware Engine

What is stMalwareDetected?

This read-only Counter64 tallies the number of infections the McAfee Gateway Anti-Malware Engine has detected. A sudden spike in this counter is worth investigating immediately as a sign of an active malware outbreak or targeted attack against users behind this gateway.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.1230.2.7.2.1.2
snmpwalk -v2c -c public <target> MCAFEE-MWG-MIB::stMalwareDetected

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.1230.2.7.2.1.2.1
snmpget -v2c -c public <target> MCAFEE-MWG-MIB::stMalwareDetected.1

Start monitoring McAfee Web Gateway appliances with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the MCAFEE-MWG-MIB::stMalwareDetected OID value, configure state conditions and alerts, and monitor any McAfee Web Gateway appliances from a single console.

How to Use in IPNetwork Monitor

Select a McAfee Web Gateway appliance as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type stMalwareDetected into the Find box to locate it in the OID tree, then select it and click OK. It reports the number of infections detected by the McAfee Gateway Antimalware Engine. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter64-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.

OID Breakdown

Upper-level ancestors (8 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.1230mcafeeMCAFEE-SMI
1.3.6.1.4.1.1230.2mcafeeGATEWAYMCAFEE-SMI
Numeric OIDNameModule
1.3.6.1.4.1.1230.2.7mwgMCAFEE-MWG-MIB
1.3.6.1.4.1.1230.2.7.2mwgStatisticsMCAFEE-MWG-MIB
1.3.6.1.4.1.1230.2.7.2.1mwgContentMCAFEE-MWG-MIB
1.3.6.1.4.1.1230.2.7.2.1.2stMalwareDetectedMCAFEE-MWG-MIB