Threat Prevention settings that apply to all on-access and on-demand scans include the quarantine location, potentially unwanted programs, and detection exclusions. Administrators can now suppress false positives by excluding files using their unique MD5 hash values.
These settings apply to all scans:
Quarantine location and the number of days to keep quarantined items before automatically deleting them.
Detection names and hashes to exclude from scans, including buffer exclusions and command-line suppression for AMSI scanning.
Potentially unwanted programs to detect, such as spyware and adware.
Trellix GTI -based telemetry feedback