The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Add Exclusion or Edit Exclusion

Prev Next

You can exclude an executable from on-access scans or on-demand scans.

Trellix ENS treats all file and folder exclusions as case insensitive — all case variations of the specified locations are excluded. For example, if you exclude C:\Temp\ABC, Trellix ENS also excludes C:\temp\abc and C:\TEMP\Abc.

Options
Section Option Definition Scan type
On-Access On-Demand
What to exclude Specifies the type of exclusion and the details for the exclusion.
File name or path Specifies the file name, path, or full path including file name to exclude.

The file name or path can include wildcards.

  • Question mark (?) matches any single character.

    You can use a single ? character as the root of a file path. For example, ?:\ABC matches the root-level ABC folder for all drives.

  • Asterisk (*) matches multiple characters, except (\) backslash.

    Note

    To exclude a folder on Windows systems, append a backslash (\) character to the path.

  • Double asterisk (**) matches multiple characters including backslash

Select Also exclude subfolders if needed.

File name exclusions can't include the following characters: | " / < >

File type Specifies file types (file extensions) to exclude.

The file type can include wildcards, but must include one non-wildcard character.

To specify a file with no extension, use ::: (3 colon characters).

File type exclusions can't include the following characters: | " / < > . *

File age Specifies the access type of files to exclude and the Minimum age in days.
  • Created — Files created n days or more ago.
  • Changed — Files last changed n days or more ago
  • Accessed — Files last accessed n days or more ago (on-demand scans only).
When to exclude Specifies when to exclude the selected item.
When writing to or reading from disk Excludes from scanning when files are being written to or read from disk or other data storage device.
When writing to disk Excludes from scanning when files are being written to or changed on the disk or other data storage device.
When reading from disk Excludes from scanning when files are being read from the computer or other data storage device.

Note

If you want to exclude items from Trellix (ENS) Adaptive Threat Protection scanning only, select this option. Threat Prevention still scans those items when they are being written to or changed on the disk.