The on-access scan protects your Mac from threats in real time. It scans for malware and takes action according to the standard settings that you configure for a process.
Click the Trellix menulet
on the status bar, then select Preferences.On the Threat Prevention tab, click
, type the administrator password, then click OK.Click On-access Scan tab.
In Maximum scan time (in seconds), specify the duration allowed to scan each file.
You can specify a value between 10 and 9999. The default value is 45. When scanning exceeds the defined time, the software stops scanning the file.
In Process Settings, select Use Standard settings for all processes to apply standard settings when performing on-access scan.
Click Configure settings.
In the Standard settings tab, configure the following:
In...
Configure...
When to scan
When writing to disk — Scans files when they are written to.
When reading from disk — Scans all files when they are read.
When reading/writing — Scans files when written to or read.
Let Trellix decide — Scans files using trust logic to optimize scanning. Trust logic improves your security and boosts performance avoiding unnecessary scans.
File Types to Scan
All files — Scans files with any extension.
Default and specified file types — Scans files with extensions defined in the software, and the extensions you specify.
For the list of the default file types, see Trellix Knowledge Base article KB79626.
Scan for macros — Enables scanning for macros in all files. This option is available only when you select Default and specified file types.
You can specify file extensions in Enter file types (comma-separated).
Specified file types only — Scans files with the extensions you specify. You can specify file extensions in Enter file types (comma-separated).
All files with no extension — Scans files with no extensions.
What to scan
On network drives — Scans files in mounted-network volumes.
Compressed archive files — Scans the contents of compressed archive files.
Caution
Scanning compressed archive files requires additional time.
Compressed MIME-encoded files — Scans Apple email messages.
Additional scan options
Detect unwanted programs — Enables the scanner to detect potentially unwanted programs.
Detect unknown program threats — Enables the scanner to detect unknown programs.
Detect unknown macro threats — Enables the scanner to detect unknown macro threats.
Actions: Threat detection first response
Clean files — Removes threats from the detected file.
Delete files — Deletes files that contain malware.
Deny access to files — Prevents users from accessing any files with potential threats.
You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.
In Unwanted program first response:
Clean files — Removes the threat from the detected file.
Delete files — Deletes the file that contains threats.
Deny access to files — Prevents users from accessing files with potential threats.
Allow access to files — Allows users to access the detected file.
Exclusions section
+ — To add files to the exclusion list.
- — To remove the selected item from the exclusion list.
Read/Write — Select one of the following options:
Read/Write — Excludes from scanning on a file read and file write.
Read — Excludes from scanning when the file is accessed.
Write — Excludes from scanning when the file is changed.
Includes Subfolders — Includes subfolders as well to exclude from scanning.
Click Close to save the settings and close the wizard.