The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Analyze AMSI Detections

Prev Next

When investigating AMSI events in the Event Log of your ENS client, review the following fields to determine the source of the detection:

  • Detected Module - Identifies the specific DLL or module loaded by the process that triggered the event.

  • Detection Context - Provides technical details about the API call or memory content associated with the detection.

Use these fields to verify if the detection is caused by a known, legitimate third-party application. Follow these steps to

View detailed AMSI event data
  1. Log on to the ENS client.

  2. Select Event Log.

    The page shows any events that Trellix ENS has logged on the system in the last 30 days.

  3. From the filter drop-down list, select Adaptive Threat Protection to view only those events.

  4. Click the specific event to open the Event Information page:

    • Detected Module: Displays the name of the file or module (for example, example.dll) that triggered the detection.

    • Detection Context: Displays the technical context of the detection, such as the specific API call.

    • Hash: Displays the SHA-256 hash of the detected module.

    Note

    You can also use Hash value from the event log to create a suppression rule in the Options policy. For more details, Configure settings for all scans.