Schedule an on-demand scan to run immediately, at a scheduled time, or at regular intervals.
Click the Trellix menulet
on the status bar, then select Preferences.On the Threat Prevention tab, click On-Demand Scan.
Click
, type the administrator password, then click OK.Configure the following:
In...
Configure...
What to scan
Archives & Compressed Files — Scans the contents of compressed archive files.
Note
Scanning compressed archive files requires additional time.
Apple Mail Messages — Scans Apple email messages.
Network Volumes — Scan files copied from or written to any network volumes.
Trellix GTI
Enable Trellix GTI — Enables Trellix GTI, a heuristic network look up for suspicious files.
Select the Sensitivity level as required:
Very Low — The detections and risk of false positives are the same as with regular DAT content files. A detection is made available to Threat Prevention when Trellix Advanced Research Center publishes it instead of waiting for the next DAT content file update.
Low — This setting is the minimum recommendation for systems with a strong security footprint.
Medium — Use this level when the regular risk of exposure to malware is greater than the risk of a false positive. Trellix Advanced Research Center proprietary, heuristic checks result in detections that are likely to be malware. However, some detections might result in a false positive. With this setting, Trellix Advanced Research Center checks that popular applications and operating system files don't result in a false positive.
High — Use this setting for deployment to systems or areas which are regularly infected.
Very High — Detections found with this level are presumed malicious, but haven't been fully tested to determine if they are false positives. Trellix recommends to use this level for systems that require highest security.
Exclusions section
Click Manage Exclusions to specify exclusions:
+ — To add files or folders to the exclusion list.
- — To remove the selected item from the exclusion list.
Actions
In Threat detection first response:
Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.
Clean files — Removes the threat from the detected file.
Delete files — Delete the file that contains malware.
You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.
In Unwanted program first response:
Continue scanning — Continues scanning files when a threat is detected. The scanner doesn't move items to the quarantine.
Clean files — Removes the threat from the detected file.
Delete files — Delete the file that contains malware.
You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.
Scheduled Scan Options
Scan only when the system is idle — Runs the scan only when the system is idle. The system is considered as idle when there is no keyboard or mouse activity for 5 minutes.
Note
The User can resume paused scans option is not supported for Mac systems.
Scan anytime — Runs the scan even if the user is active and specifies options for the scan.
Note
The User can defer scans, User can pause and cancel scans, and Do not scan when the system is in presentation mode options are not supported for Mac systems.
Do not scan when the system is on battery power — Postpones the scan when the system is using battery power.
Click
to prevent further changes.For information about creating a scan task, see Create a scan task.