The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Configure scans that run automatically when files are accessed on a client system

Prev Next

On-access scan configuration includes settings based on process type, and defining messages to send when a threat is detected.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Threat Prevention on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Threat Prevention on the Settings page.

  3. Click Show Advanced.

  4. Click On-Access Scan.

  5. Select Enable On-Access Scan to enable the on-access scanner and change options.

  6. Specify whether to use Standard settings for all processes, or different settings for high-risk and low-risk processes.

    • Use Standard settings for all processes — Configure the scan settings on the Standard tab.

    • Configure different settings for High Risk and Low Risk processes — Select the tab (Standard, High Risk, or Low Risk) and configure the scan settings for each process type.

  7. Click Apply.