Create an on-access policy to enable or disable on-access scan, define scanning time limit for each file, and to define exclusions.
For details about product features, usage, and best practices, click ? or Help.
Log on to the ePO - On-prem server as an administrator.
From the Policy Catalog, select Endpoint Security Threat Prevention as the product, then select On-Access Scan as the category.
Click New Policy, type a name for the policy, then click OK.
Click the policy that you created, click Show Advanced.
In the On-Access Scan section, define these settings.
In...
Configure...
On-Access Scan
Enable On-Access Scan — Enables or disables on-access scanning on managed system.
Specify maximum number of seconds for each file scan — Specify the scan timeout value to scan each item. If you deselect this option, the value is set to 45 seconds.
Trellix GTI
Enable Trellix GTI — Enables Trellix GTI, a heuristic network look up for suspicious files.
Select the Sensitivity level as required:
Very low — The detections and risk of false positives are the same as with regular DAT content files. A detection is made available to Threat Prevention when Trellix Advanced Research Center publishes it instead of waiting for the next DAT content file update.
Low — This setting is the minimum recommendation for systems with a strong security footprint.
Medium — Use this level when the regular risk of exposure to malware is greater than the risk of a false positive. Trellix Advanced Research Center proprietary, heuristic checks result in detections that are likely to be malware. However, some detections might result in a false positive. With this setting, Trellix Advanced Research Center checks that popular applications and operating system files don't result in a false positive.
High — Use this setting for deployment to systems or areas which are regularly infected.
Very high — Detections found with this level are presumed malicious, but haven't been fully tested to determine if they are false positives. Trellix recommends to use this level for systems that require highest security.
Note
For Trellix Endpoint Security (ENS) for Linux, if a low-risk process spawns subprocesses, those subprocesses are also considered low-risk; therefore, there is no need to manually categorize them as low-risk.
Process Settings
Depending on the process or program through which a file is accessed, Threat Prevention categorizes the risk level as high risk process and low risk process. If the process doesn't fall under these categories, it is considered as standard process.
Use Standard settings for all processes — Applies standard settings when performing on-access scanning.
Configure different settings for High Risk and Low Risk processes — Applies different scanning settings for each process type that you identify. You can add, edit. or remove process and its type as required.
In the Standard High Risk Low Risk process type:
In When to scan:
When writing to disk — Scans files when they are written to.
When reading from disk — Scans all files when they are read.
Let Trellix decide — Scans files when written to or read.
Do not scan when reading from or writing to disk — Doesn't scan files when reading from or writing operation. This is applicable only to Low Risk process.
In What to scan:
All files — Scans files with any extension.
Default and specified file types — Scans files with extensions defined in the software, and the extensions you specify.
For the list of default files that are scanned when Default and Specified file types option is selected, see Trellix Knowledge Base article KB79626.
Scan for Macros — Enables scanning for macros in all files.
Specified file types only — Scans only files with extensions that you specify, and optionally, files with no extension.
On network drives — Scans files in mounted-network volumes.
Compressed archive files — Scans the contents of compressed archive files.
Caution
Scanning compressed archive files requires additional time.
Compressed MIME-encoded files — Scans Multipurpose Internet Mail Exchange email messages.
In Additional scan options:
Detect unwanted programs — Enables the scanner to detect potentially unwanted programs.
Detect unknown program threats — Enables the scanner to detect unknown programs.
Detect unknown macro threats — Enables the scanner to detect unknown macro threats.
In Actions → Threat detection first response:
Deny access to files — Prevents users from accessing any files with potential threats.
Delete files — Deletes files that contain malware.
Clean files — Removes threats from the detected file.
You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.
In Unwanted program first response:
Clean files — Removes the threat from the detected file.
Delete files — Deletes the file that contains threats.
Deny access to files — Prevents users from accessing files with potential threats.
Allow access to files — Allows users to access the detected file.
Scan Timeout response — Action to take when scanning timeout for a file.
Scan Error Response — Action to take when scan fails with error.
You can also configure a secondary response using the If first response fails option, in case the primary response is unsuccessful.
In the Exclusions section, click:
Add — To add files to the exclusion list.
Edit — To edit the exclusion settings.
Delete — To remove the selected item from the exclusion list.
Clear All — To remove all items from the exclusion list.
Enable Overwrite exclusions configured on the client to overwrite the exclusions list created by the managed system user.
For more information about configuring exclusions, see Exclude files or directories from scanning.
Click Save.