The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Adaptive Threat Protection — Options

Prev Next

You can configure settings for the Adaptive Threat Protection module, including ML Protect scanner behavior, enhanced script scanning, and the rule groups to use for calculating reputations.

Options
Section Option Definition
Options Enable Adaptive Threat Protection Enables the Adaptive Threat Protection module.

(Enabled by default)

Enable Observe mode Generates Adaptive Threat Protection events (Would Block, Would Clean, or Would Contain) and sends them to the server, but doesn't enforce actions.

(Disabled by default)

Enable Observe mode temporarily on a few systems only while tuning Adaptive Threat Protection.

Observe mode applies to all Adaptive Threat Protection features, including ML Protect and Dynamic Application Containment.

Caution

Because enabling this mode causes Adaptive Threat Protection to generate events but not enforce actions, your systems might be vulnerable to threats.

Allow the Threat Intelligence Exchange server to collect anonymous diagnostic and usage data Allows the TIE server to send anonymous file information to Trellix.

(Enabled by default)

Scan processes started from network drives Scans processes that are started from mapped network drives.

(Disabled by default)

Tip

Best practice: Deselect this option to improve performance.

ML Protect Scanning Enable client-based scanning Enables client-based ML Protect scanning, which uses machine learning on the client system to determine whether the file matches known malware.

(Enabled by default)

If the client system is connected to the Internet, ML Protect sends telemetry information to the cloud, but doesn't get automated analysis data from the cloud.

Client-based scanning requires Adaptive Threat Protection or TIE server connectivity unless offline scanning is enabled.

Tip

Best practice: Select this option unless Support advises you to deselect it to mitigate false positives.

The ML Protect technology is not supported on some Windows operating systems. See KB82761 for information.

Enable offline scanning Enables client-based ML Protect scanning to run offline, without requiring connectivity to Trellix GTI or the TIE server.

(Disabled by default)

Tip

Best practice: Because offline scanning might result in increased false positives, enable this option only for systems without connectivity to Trellix GTI or the TIE server.

Sensitivity level Configures the sensitivity level to use with client-based scanning when determining whether the file matches known malware.
  • Low
  • Medium
  • High

The higher the sensitivity level, the more malware matches. But, allowing more detections might result in more false positives.

Enable cloud-based scanning Enables cloud-based ML Protect scanning, which collects the attributes of the file and its behavioral information. Then, it sends this information to the machine-learning system in the cloud for analysis.

(Enabled by default)

Cloud-based scanning requires connectivity to https://arc-ai1.trellix.com/.

Tip

Best practice: Disable cloud-based ML Protect on systems that aren't connected to the Internet.

The ML Protect technology is not supported on some Windows operating systems. See KB82761 for information.

Enable enhanced script scanning Enables integration with AMSI (Antimalware Scan Interface).

Select this option to enhance scanning for threats in non-browser-based scripts, such as PowerShell, JavaScript, and VBScript.

(Enabled by default)

AMSI is a generic interface standard provided by Microsoft and supported on Windows 10, Windows Server 2016, and Windows 2019 systems. It allows applications and services to integrate with Adaptive Threat Protection, providing better protection against malware.

Enable Observe mode Generates ML Protect enhanced scanning events (Would Block and Would Clean) and sends them to the server, but doesn't enforce actions.

(Enabled by default)

AMSI excludes most files that are excluded from on-access scans. Some scripts, such as PowerShell, are fileless and are not excluded from AMSI.

Enable enhanced scanning Observe mode temporarily on a few systems only while tuning ML Protect to evaluate the impact of ML Protect enhanced scanning.

Caution

Because enabling this mode causes enhanced scanning to generate events but not enforce actions, your systems might be vulnerable to threats.

Enable Credential Theft Protection Scanning Enables Credential Theft Protection scanning on client systems.

(Enabled by default)

Enable Credential Theft Protection Observe mode Enables Credential Theft Protection Observe Mode on client systems. When this feature is enabled, Adaptive Threat Protection events are generated and sent to Trellix ePO - On-prem automatically.

(Disabled by default)

Rule Assignment Specifies the set of rules that Adaptive Threat Protection uses to calculate a reputation.

Control rules and view reputations in Server SettingsAdaptive Threat Protection.

Note

The Productivity, Balanced, and Security rule groups are different from, and don't affect the Dynamic Application Containment policies, Trellix Default Balanced and Trellix Default Security.

Productivity Assigns the Productivity rule group.

Use this group for high-change systems with frequent installations and updates of trusted software.

This group uses the least number of rules. Users experience minimum prompts and blocks when new processes are detected.

Balanced Assigns the Balanced rule group.

Use this group for typical business systems with infrequent new software and changes.

This group uses more rules — and users experience more prompts and blocks — than the Productivity group.

Security Assigns the Security rule group.

Use this group for low-change systems, such as IT-managed systems and servers with tight control.

Users experience more prompts and blocks than with the Balanced group.

Action Enforcement Trigger Dynamic Application Containment when reputation threshold reaches Contains applications when the reputation reaches the specified threshold:
  • Might Be Trusted
  • Unknown (default for the Security rule group)
  • Might Be Malicious (default for the Balanced rule group)
  • Most Likely Malicious (default for the Productivity rule group)
  • Known Malicious

The Dynamic Application Containment reputation threshold must be above the block and clean thresholds. For example, if the block threshold is set to Known Malicious, the Dynamic Application Containment threshold must be set to Most Likely Malicious or above.

When an application with the specified reputation threshold tries to run in your environment, Dynamic Application Containment allows it to run in a container and blocks or logs unsafe actions, based on containment rules.

If configured, Dynamic Application Containment updates the Event Log in the Endpoint Security Client to notify you when:

  • An application has been contained.
  • A contained application attempts to violate the containment rules.
Block when reputation threshold reaches Blocks files when the file reputation reaches a specific threshold, and specifies the threshold:
  • Might Be Trusted
  • Unknown
  • Might Be Malicious (default for the Security rule group)
  • Most Likely Malicious (default for the Balanced rule group)
  • Known Malicious (default for the Productivity rule group)

When a file with the specified reputation threshold tries to run in your environment, it's prevented from running but remains in place. If a file is safe and you want it to run, change its reputation to a level that allows it to run, like Might be Trusted.

Clean when reputation threshold reaches Cleans files when the file reputation reaches a specific threshold, and specifies the threshold:
  • Might Be Malicious
  • Most Likely Malicious
  • Known Malicious (default for the Balanced and Security rule groups)

The default for the Productivity rule group is deselected.

Tip

Best practice: Use this option with Known Malicious file reputations because a file might be removed when cleaned.

This option must be selected to enable enhanced remediation.

Enable enhanced remediation Monitors the behavior of processes with a reputation of Unknown (50) and below, and their children, backs up, and remediates these changes that the processes make to the system:
  • All files that the process creates, but not files that it changes or deletes.
  • All changes to non-file objects, such as registry items, Windows Task Scheduler, and WMI (Windows Management Instrumentation) triggers and filters.
If a monitored process exhibits malicious behavior, enhanced remediation stops the process, its children, and ancestors, and rolls back the changes that it made, restoring the system as close as possible to its original state before the process ran.

(Enabled by default)

Enhanced remediation is available only when the Clean when reputation threshold reaches option is enabled.

Monitor and remediate deleted and changed files Backs up and remediates all files, including files that the process changes or deletes.

Because backing up all file changes might consume significant disk space and negatively impact performance, by default, enhanced remediation backs up only files that the process creates. Enable this option to also back up changed and deleted files.

Note

Enabling this option can increase the amount of disk space that monitoring consumes and negatively impact performance. With this option disabled, enhanced remediation can't roll back file changes and deletions. In addition, Trellix (ENS) Adaptive Threat Protection deletes any files renamed by the malicious process.

(Disabled by default)

Advanced options
Section Option Description
Threat Detection User Messaging Display threat notifications to the user Displays threat notifications to the user.

Adaptive Threat Protection depends on the Trellix system tray icon to display prompts. On systems accessed only by RDP, the system tray icon doesn't start and prompts don't appear. To work around this issue, add the UpdaterUI.exe to the logon script. See KB83532.

Notify the user when reputation threshold reaches Notifies the user when the file reputation reaches a specified threshold:
  • Most Likely Trusted
  • Might Be Trusted (default for the Security rule group)
  • Unknown (default for the Balanced rule group)
  • Might Be Malicious (default for the Productivity rule group)
  • Most Likely Malicious
  • Known Malicious

The prompt level can't conflict with the clean or block settings. For example, if you block unknown files, you can't set this field to Might Be Trusted because it is above Unknown.

If the notify threshold is at or above the containment threshold, when the user selects Allow, the application runs uncontained.

Default action Specifies the action to take if the user doesn't respond to the prompt:
  • Allow

    If the notify threshold is at or above the containment threshold, a default action of Allow lets the application run uncontained.

  • Block
Specify length (minutes) of timeout Specifies the number of minutes to display the prompt before performing the default action.

The default is 5 minutes.

Message Specifies the message that the user sees when a file, which meets the prompting criteria, tries to run.
Disable threat notifications if the Threat Intelligence Exchange server is not reachable Disables prompts when the TIE server is unreachable so that users don't receive prompts about files whose reputations are unavailable.
Reputation Source Use Trellix GTI if the TIE server is not reachable Gets file reputation information from the Global Threat Intelligence proxy if the TIE server is unavailable.

(Enabled by default for Trellix ePO - On-prem)

Use only the TIE server Gets file reputation information from the TIE server.
Use only Trellix GTI Gets file reputation information from Trellix GTI .

(Enabled by default for Trellix ePO - SaaS)

Sandboxing

Note

The Sandboxing option is available in MVISION ePO only if TIE is licensed.

Send files not yet verified for analysis Sends executable files to TIE server, which then sends files to Sandbox server for analysis.

When enabled, Adaptive Threat Protection sends files securely over HTTPS using port 443 when:

  • The TIE server doesn't have sandbox information about the file.
  • The file is at or below the specified reputation level.
  • The file is at or below the specified file size limit.

Specify information for the Sandbox server in the TIE settings.

Submit files when reputation threshold reaches Submits files to TIE server, which then sends files to Sandbox server when the file reputation reaches a specified threshold:
  • Most Likely Trusted
  • Unknown
  • Most Likely Malicious

The default for all rule groups is Unknown.

Limit size (MB) to Limits the size of the files sent to Sandbox server to between 1 MB and 10 MB.

The default is 5 MB.

Story Graph Enable Story Graph Tracing

The Story Graph in the Threat Event Log provides a visual representation of file-based and fileless-based ATP threat detection. You can examine the context of threats by reviewing the details of events leading up to a detection.