The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configuring policy exclusions

Prev Next

To improve performance and avoid generating false positive alerts, add the script or application to the exclusion list.

To configure exclusions:

  1. Log in to the Endpoint Security Web UI.

  2. From the Admin menu, select Polices.

  3. On the Policies page, select the policy you want.

  4. On the Edit Policy page, in the Configurations section, select the AMSI tab.

  5. On the AMSI details panel, in the Policy Exclusion section, enter the appropriate values to complete the exclusion.

  6. In the Parameter Name field, select the appropriate endpoint.

    AMSI_NewExclusion.png
  7. In the Match Criteria field, select the appropriate operator.

  8. In the Parameter Value field, enter the value.

    To find the parameter value, click the Alerts tab, select an AMSI alert from the grid, and click Alert Summary. For more information, see Alert details.

    AMSI_AlertSummary.PNG
  9. Click Save Exclusion.

Note

DTI intel updates may add exclusions to disable detections that generate excessive false positive alerts.