The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure the On-access Scan policy

Prev Next

Create an on-access policy to enable or disable on-access scan, define scanning time limit for each file, and to define exclusions.

  1. Log on to the ePO - On-prem server as an administrator.

  2. From the Policy Catalog, select Endpoint Security Threat Prevention as the product, then select On-access Scan as the category.

  3. Click New Policy, type a name for the policy, then click OK.

  4. Click the policy that you created, click Show Advanced.

  5. In the On-access Scan section, define these settings.

    In...

    Configure...

    On-access Scan

    • Enable On-access Scan — Enables or disables on-access scanning on managed system.

    • Specify maximum number of seconds for each file scan — Specify the scan timeout value to scan each item. If you deselect this option, the value is set to 45 seconds.

    Trellix GTI

    • Enable Trellix GTI — Enables Trellix GTI, a heuristic network look up for suspicious files.

    Select the Sensitivity level as required:

    • Very Low — The detections and risk of false positives are the same as with regular DAT content files. A detection is made available to Threat Prevention when Trellix Advanced Research Center publishes it instead of waiting for the next DAT content file update.

    • Low — This setting is the minimum recommendation for systems with a strong security footprint.

    • Medium — Use this level when the regular risk of exposure to malware is greater than the risk of a false positive. Trellix Advanced Research Center proprietary, heuristic checks result in detections that are likely to be malware. However, some detections might result in a false positive. With this setting, Trellix Advanced Research Center checks that popular applications and operating system files don't result in a false positive.

    • High — Use this setting for deployment to systems or areas which are regularly infected.

    • Very High — Detections found with this level are presumed malicious, but haven't been fully tested to determine if they are false positives. Trellix recommends to use this level for systems that require highest security.

    Process Settings

    Depending on the process or program through which a file is accessed, Threat Prevention categorizes the risk level as high risk process and low risk process. If the process doesn't fall under these categories, it is considered as standard process.

    Note

    To configure High Risk and Low Risk processes, you need to install Endpoint Security for Mac License extension.

    Use Standard settings for all processes — Applies standard settings when performing on-access scanning.

    In the Standard process type:

    • In When to scan:

      • When writing to disk — Scans files when they are written to.

      • When reading from disk — Scans all files when they are read.

      • Let Trellix decide — Scans files when written to or read.

    • In What to scan:

      • All files — Scans files with any extension.

      • Default and specified file types — Scans files with extensions defined in the software, and the extensions you specify.

        For the list of the default file types, see Trellix Knowledge Base article KB79626.

      • Scan for Macros — Enables scanning for macros in all files.

      • Specified file types only — Scans only files with extensions that you specify, and optionally, files with no extension.

    • On network drives — Scans files in mounted-network volumes.

    • Compressed archive files — Scans the contents of compressed archive files.

      Caution

      Scanning compressed archive files requires additional time.

    • Compressed MIME-encoded files — Scans Apple email messages.

    • In Additional scan options:

    • Detect unknown macro threats — Enables the scanner to detect unknown macro threats.

    In ActionsThreat detection first response:

    • Deny access to files — Prevents users from accessing any files with potential threats.

    • Delete files — Deletes files that contain malware.

    • Clean files — Removes threats from the detected file.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    In Unwanted program first response:

    • Clean files — Removes the threat from the detected file.

    • Delete files — Deletes the file that contains threats.

    • Deny access to files — Prevents users from accessing files with potential threats.

    • Allow access to files — Allows users to access the detected file.

    You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.

    In the Exclusions section, click:

    • Add — To add files to the exclusion list.

    • Edit — To edit the exclusion settings.

    • Delete — To remove the selected item from the exclusion list.

    • Clear All — To remove all items from the exclusion list.

    Enable Overwrite exclusions configured on the client to overwrite the exclusions list created by the managed system user.

    For more information about configuring exclusions, see Exclude files or directories from scanning.

  6. Click Save.