The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure On-Demand Scan policy (Full Scan)

Prev Next

Configure On-Demand Full Scan policy settings for your managed system.

  1. Log on to ePO - On-prem as an administrator.

  2. From the Policy Catalog, select Endpoint Security Threat Prevention as the product, then select On-Demand Scan as the category.

  3. Click New Policy, type a name for the policy, then click OK.

  4. Click the policy that you created, click the Full Scan tab, then define these settings.

    In...

    Configure...

    What to Scan

    • Compressed MIME-encoded files — Detects, decodes, and scans Multipurpose Internet Mail Extensions (MIME) encoded files.

    • Compressed archive files — Scans the contents of compressed archive files.

      Note

      Scanning compressed archive files requires additional time.

    Additional Scan Options

    • Detect unwanted programs — Enables the scanner to detect potentially unwanted programs.

    • Detect unknown program threats — Detects files that contain code resembling malware.

    • Detect unknown macro threats — Detects unknown macro threats.

    Scan Locations

    • Scan subfolders — Examines all subfolders in the specified volumes when any of these options are selected.

      • Temp folder — Directories with the name /var/tmp and/tmp are scanned.

      • File or folder — Scans only the Linux-specific path.

      • All local drives — Any mounted file system that is not a specified file system or a network file system.

      • All mapped drives — Any mounted file system type of NFS, CIFS, or SMBFS is considered as a mapped drive. When you select this option, all such file systems are scanned.

    You can add locations by clicking GUID-2E3ED0C4-CEA9-4CB8-9253-F92BAC4B3F7B-low.png. Click GUID-B312C0D9-FC8E-483D-AA90-610D5BED19AF-low.png to remove the locations from scanning.

    File Types to Scan

    • All files — Scans all files regardless of extension.

      Note

      Trellix strongly recommends that you enable All files to make sure that no malware threat resides in your managed systems.

    • Default and specified file types — Scans files with extensions defined in the software and extensions you specify.

      For the list of default files that are scanned when Default and Specified file types option is selected, see Trellix KnowledgeBase article KB79626.

    • Scan for macros — Enables scanning for macros in all files.

    • Specified file types only — Scans only files with extensions that you specify. Select Include files with no extension to scan files that contain no extension.

    Trellix GTI

    • Enable Trellix GTI — Enables Trellix GTI, a heuristic network look up for suspicious files.

    Select the Sensitivity level as required:

    • Very low — The detections and risk of false positives are the same as with regular DAT content files. A detection is made available to Threat Prevention when Trellix Advanced Research Center publishes it instead of waiting for the next DAT content file update.

    • Low — This setting is the minimum recommendation for systems with a strong security footprint.

    • Medium — Use this level when the regular risk of exposure to malware is greater than the risk of a false positive. Trellix Advanced Research Center proprietary, heuristic checks result in detections that are likely to be malware. However, some detections might result in a false positive. With this setting, Trellix Advanced Research Center checks that popular applications and operating system files don't result in a false positive.

    • High — Use this setting for deployment to systems or areas which are regularly infected.

    • Very high — Detections found with this level are presumed malicious, but haven't been fully tested to determine if they are false positives. Trellix recommends to use this level for systems that require highest security.

    Exclusions

    In the Exclusions section, click:

    • Add — To add files to the exclusion list.

    • Edit — To edit the exclusion settings.

    • Delete — To remove the selected item from the exclusion list.

    • Clear All — To remove all items from the exclusion list.

    For more information about configuring exclusions, see Exclude files or directories from scanning.

    Actions

    In Threat detection first response:

    • Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.

    • Clean files — Removes the threat from the detected file.

    • Delete files — Delete the file that contains malware.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    For Linux, when the action is set to Deny, on detection, the actual file write operation is not stopped. However, the subsequent action is denied.

    In Unwanted program first response:

    • Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.

    • Clean files — Removes the threat from the detected file.

    • Delete files — Delete the file that contains malware.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    If all actions fail, the fallback action is deny access.

    Performance

    • Use the scan cache — Enables the scanner to use the existing clean scan results.

    • Specify maximum number of seconds for each file scan — Limits each file scan to the specified number of seconds. The default value is 45 seconds, and this option is enabled by default. If a scan exceeds the time limit, the scan stops cleanly and logs a message.

    • Specify maximum number of threads allowed — Limits the number of on-demand scan threads that can run simultaneously.

    • Limit maximum CPU usage (Available only when Scan anytime is selected) — Limit the CPU usage when you run on-demand scan tasks. The default value is 80. You can specify the value 25 to 100.

  5. Click Save.

    For scheduling the task, see the product guide for your version of ePO - On-prem.

    Note

    Trellix Endpoint Security (ENS) for Linux does not support the Right-Click Scan option.