Threat Prevention settings that apply to all on-access and on-demand scans include the quarantine location, potentially unwanted programs, and detection exclusions. Administrators can now suppress false positives by excluding files using their unique MD5 hash values.
Note
Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.
These settings apply to all scans:
Quarantine location and the number of days to keep quarantined items before automatically deleting them.
Use exclusions to prevent false positives in your environment. These settings do not prevent scans, they only manage detections.
Detection Name: Excludes detections based on the detection name.
Hash: Excludes detections based on the file hash. Supported formats include MD5, SHA-1, and SHA-256 in hexadecimal.
Buffer-hash: Suppresses Advanced Malware Scanning Interface (AMSI) detections.
Command-line: Suppresses AMSI detections.
Potentially unwanted programs to detect, such as spyware and adware.
Trellix GTI -based telemetry feedback