The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure on-access scan preferences (high risk and low risk settings)

Prev Next

The on-access scan protects your Mac from threats in real time. It scans for malware and takes action based on the scan settings for the process type associated with the process accessing the file. You can add, edit, or remove process and its type as required.

  1. Click the Trellix menulet GUID-9BE2692D-7F54-44CB-AE3B-3D141955024E-low.png on the status bar, then select Preferences.

  2. On the Threat Prevention tab, click GUID-8CC2C84C-B44D-4B10-A920-D4E503DB9CC1-low.png, type the administrator password, then click OK.

  3. Click On-access Scan tab.

  4. In Maximum scan time (in seconds), specify the duration allowed to scan each file.

    You can specify a value between 10 and 9999. The default value is 45. When scanning exceeds the defined time, the software stops scanning the file.

  5. In Process Settings, select Configure High/Low Risk process settings to apply separate on-access scan settings, based on the risk associated with the processes. You can add, edit, or remove process and its process type.

  6. Click Configure settings.

  7. In the High Risk tab, configure the following:

    In...

    Configure...

    When to scan

    • When writing to disk — Scans files when they are written to.

    • When reading from disk — Scans all files when they are read.

    • When reading/writing — Scans files when written to or read.

    • Let Trellix decide — Scans files using trust logic to optimize scanning. Trust logic improves your security and boosts performance avoiding unnecessary scans.

    File Types to Scan

    • All files — Scans files with any extension.

    • Default and specified file types — Scans files with extensions defined in the software, and the extensions you specify.

      For the list of the default file types, see Trellix Knowledge Base article KB79626.

      • Scan for macros — Enables scanning for macros in all files. This option is available only when you select Default and specified file types.

      • You can specify file extensions in Enter file types (comma-separated).

    • Specified file types only — Scans files with the extensions you specify. You can specify file extensions in Enter file types (comma-separated).

      • All files with no extension — Scans files with no extensions.

    What to scan

    • On network drives — Scans files in mounted-network volumes.

    • Compressed archive files — Scans the contents of compressed archive files.

      Caution

      Scanning compressed archive files requires additional time.

    • Compressed MIME-encoded files — Scans Apple email messages.

    Additional scan options

    • Detect unwanted programs — Enables the scanner to detect potentially unwanted programs.

    • Detect unknown program threats — Enables the scanner to detect unknown programs.

    • Detect unknown macro threats — Enables the scanner to detect unknown macro threats.

    Actions: Threat detection first response

    • Deny access to files — Prevents users from accessing any files with potential threats.

    • Delete files — Deletes files that contain malware.

    • Clean files — Removes threats from the detected file.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    In Unwanted program first response:

    • Clean files — Removes the threat from the detected file.

    • Delete files — Deletes the file that contains threats.

    • Deny access to files — Prevents users from accessing files with potential threats.

    • Allow access to files — Allows users to access the detected file.

    Exclusions section

    • + — To add files to the exclusion list.

    • - — To remove the selected item from the exclusion list.

    • Read/Write — Select one of the following options:

      • Read/Write — Excludes from scanning on a file read and file write.

      • Read — Excludes from scanning when the file is accessed.

      • Write — Excludes from scanning when the file is changed.

      • Includes Subfolders — Includes subfolders as well to exclude from scanning.

  8. In the Low Risk tab, configure the following:

    In...

    Configure...

    When to scan

    • When writing to disk — Scans files when they are written to.

    • When reading from disk — Scans all files when they are read.

    • When reading/writing — Scans files when written to or read.

    • Let Trellix decide — Scans files using trust logic to optimize scanning. Trust logic improves your security and boosts performance avoiding unnecessary scans.

    • Do not scan — Skips files from scanning.

    File Types to Scan

    • All files — Scans files with any extension.

    • Default and specified file types — Scans files with extensions defined in the software, and the extensions you specify.

      For the list of the default file types, see Trellix Knowledge Base article KB79626.

      • Scan for macros — Enables scanning for macros in all files. This option is available only when you select Default and specified file types.

      • You can specify file extensions in Enter file types (comma-separated).

    • Specified file types only — Scans files with the extensions you specify. You can specify file extensions in Enter file types (comma-separated).

      • All files with no extension — Scans files with no extensions.

    What to scan

    • On network drives — Scans files in mounted-network volumes.

    • Compressed archive files — Scans the contents of compressed archive files.

      Caution

      Scanning compressed archive files requires additional time.

    • Compressed MIME-encoded files — Scans Apple email messages.

    Additional scan options

    • Detect unwanted programs — Enables the scanner to detect potentially unwanted programs.

    • Detect unknown program threats — Enables the scanner to detect unknown programs.

    • Detect unknown macro threats — Enables the scanner to detect unknown macro threats.

    Actions: Threat detection first response

    • Deny access to files — Prevents users from accessing any files with potential threats.

    • Delete files — Deletes files that contain malware.

    • Clean files — Removes threats from the detected file.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    In Unwanted program first response:

    • Clean files — Removes the threat from the detected file.

    • Delete files — Deletes the file that contains threats.

    • Deny access to files — Prevents users from accessing files with potential threats.

    • Allow access to files — Allows users to access the detected file.

    Exclusions section

    • + — To add files to the exclusion list.

    • - — To remove the selected item from the exclusion list.

    • Read/Write — Select one of the following options:

      • Read/Write — Excludes from scanning on a file read and file write.

      • Read — Excludes from scanning when the file is accessed.

      • Write — Excludes from scanning when the file is changed.

      • Includes Subfolders — Includes subfolders as well to exclude from scanning.

  9. Click Close to save the settings and close the wizard.