The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Custom on-demand scan command line interface

Prev Next

With the custom on-demand scan command line interface, you can run a previously defined custom on‑demand scan with new settings, without changing the settings of the original custom scan.

Threat Prevention creates a clone of the original custom on-demand scan, applies your changes to the settings, and logs the changes. The new cloned custom scan is named as <name>_cloned. The <name> refers to original custom on-demand scan. Once the scan is completed, the clone is available for 15–20 minutes. The original scan settings remain unchanged.

Note

You can't change the Quick Scan or Full Scan with the command line interface.

Prerequisites

  • The Threat Prevention service (mfetp.exe) must already be running for amcfg.exe to run.

  • The interface mode for the Trellix Endpoint Security (ENS) Client must be set to Full access if a user wants to stop, pause or resume an on-demand scan through command line.

    All users can start a scan and check the status of a scan, regardless of the interface mode for the Trellix Endpoint Security (ENS) Client.

Syntax: Custom on-demand scan command line interface

The custom on-demand scan syntax for amcfg.exe is:

installation_path\amcfg.exe /scan [ /list | /task /scan_ID [ command_args ] [ /action start ] ] 
  • installation_path — C:\Program Files\McAfee\Endpoint Security\Threat Prevention by default

  • command_args— One of the commands in the Custom on‑demand scan command arguments table

Arguments can appear in any order, except that you must keep each argument with its value.

The scan is executed only if all values are correct. Otherwise, amcfg.exe displays a message with the possible values and doesn't run the scan. If the command line includes multiple values for an argument, the scan runs using only the first value. The scanner ignores any invalid configuration arguments.

While cloning a custom scan, you can add new /targets with already defined custom scan task. The new cloned custom scan, <name>_cloned, not only scans the new /targets but also the paths mentioned in the original custom scan.

When changing a custom scan, the only valid /action argument is start. But, when a cloned scan task is running, you can apply all actions (start, pause, resume, cancel, status) to it as long as the interface mode is set to Full access.

Custom on-demand scan command arguments

Argument

Value

Description

/list

Displays the list of currently defined custom on-demand scan tasks, including temporary cloned scan tasks.

/task

scan_ID

Specifies the ID of the custom on-demand scan to change and run.

If the scan ID includes spaces, you must enclose it in double-quote characters (").

Note

Cloned scan task IDs might include spaces.

/targets

file path

Specifies a single complete file path to scan.

/insidefolders

  • 0 — Don't scan subfolders.

  • 1 — Scan subfolders.

Examines all subfolders of the specified folder.

/usecleancache

  • 0 — Don't use clean scan cache.

  • 1 — Use clean scan cache.

Enables the scanner to use the existing clean scan results.

Tip

Best practice: Select this option to reduce duplicate scanning and improve performance.

If you enable logging of files scanned during an on-demand scan, the scanner doesn't log files in the clean scan cache.

/gtisensitivity

  • 0Disabled

  • 1Very low

  • 2Low

  • 3Medium

  • 4High

  • 5Very high

Configures the Trellix GTI sensitivity level to use when determining if a detected sample is malware.

When enabled, fingerprints of samples, or hashes, are submitted to Trellix Advanced Research Center to determine if they are malware. By submitting hashes, detection might be made available sooner than the next AMCore content file release, when Trellix Advanced Research Center publishes the update.

The higher the sensitivity level, the higher the number of malware detections. But, allowing more detections might result in more false positive results.

Trellix GTI sensitivity levels are:

  • Disabled — No fingerprints or data is submitted to Trellix Advanced Research Center.

  • Very low — The detections and risk of false positives are the same as with regular AMCore content files. A detection is made available to Threat Prevention when Trellix Advanced Research Center publishes it instead of in the next AMCore content file update.

    Use this setting for desktops and servers with restricted user rights and strong security configurations.

    Average results: 10–15 queries per day, per computer.

  • Low — This setting is the minimum recommendation for laptops, desktops, and servers with strong security configurations. Average results: 10–15 queries per day, per computer.

  • Medium — Use this setting when the regular risk of exposure to malware is greater than the risk of a false positive. Trellix Advanced Research Center proprietary, heuristic checks result in detections that are likely to be malware. But, some detections might result in a false positive. With this setting, Trellix Advanced Research Center checks that popular applications and operating system files don't result in a false positive.

    This setting is the minimum recommendation for laptops, desktops, and servers.

    Average results: 20–25 queries per day, per computer.

  • High — Use this setting for deployment to systems or areas which are regularly infected. Average results: 20–25 queries per day, per computer.

  • Very high — Use this setting for non-operating system volumes. Detections found with this level are presumed malicious, but haven't been fully tested to determine if they are false positives.

    Use this setting only to scan volumes and directories that don't support executing programs or operating systems.

    Average results: 20–25 queries per day, per computer.

/sysutilization

  • 1Low

  • 2Below normal

  • 3Normal

Enables the operating system to specify the amount of CPU time that the scanner receives during the scan.

Each task runs independently, unaware of the limits for other tasks.

  • Low — Provides improved performance for other running applications. Sets the number of threads for the scan to 1.

    Tip

    Best practice: Select this option for systems with end-user activity.

  • Below normal (Default for the preconfigured Full Scan and Quick Scan) — Sets the number of threads for the scan to be equal to the number of CPUs.

  • Normal (Default for custom scans) — Enables the scan to finish faster. Sets the number of threads for the scan to twice the number of CPUs.

    Tip

    Best practice: Select this option for systems with large volumes and little end-user activity.

/firsttaction

  • 0 — Removes the threat from the detected file, if possible.

  • 1 — Deletes files with potential threats.

  • 2 — Continues scanning files, without cleaning or deleting, when a threat is detected. The scanner doesn't move items to the quarantine.

Specifies how the scanner responds when it detects a threat:

  • firsttaction — Specifies the first action for the scanner to take when a threat is detected.

  • secondtaction — Specifies the action for the scanner to take when a threat is detected if the first action fails.

  • firstpupaction — Specifies the first action for the scanner to take when a potentially unwanted program is detected.

    This option is available only if detectup is set to 1.

  • secondpupaction — Specifies the action for the scanner to take when an unwanted program detection is detected if the first action fails.

    This option is available only if detectup is set to 1.

Remember:

  • If the first action is 0, the second action can be either 1 or 2.

  • If the first action is 1, the second action must be 2.

  • If the first action is 2, the second action is disabled.

  • The second action can never be 0.

/secondtaction

/firstpupaction

/secondpupaction

/mime

  • 0 — Don't scan MIME-encoded files.

  • 1 — Scan MIME-encoded files.

Detects, decodes, and scans Multipurpose Internet Mail Extensions (MIME) encoded files.

/archive

  • 0 — Don't scan compressed archive files.

  • 1 — Scan compressed archive files.

Examines the contents of archive (compressed) files, including .jar files.

Tip

Best practice: Select this option only in scans scheduled during off hours when the system isn't being used. Scanning compressed archive files can negatively affect system performance.

/detectup

  • 0 — Don't detect unwanted programs.

  • 1 — Detect unwanted programs.

Enables the scanner to detect potentially unwanted programs. The scanner uses the information you configured in the Threat Prevention Options settings to detect potentially unwanted programs.

/detectmt

  • 0 — Don't detect unknown macro threats.

  • 1 — Detect unknown macro threats.

Enables the scanner to detect unknown macro threats.

/detectpt

  • 0 — Don't detect unknown program threats.

  • 1 — Detect unknown program threats.

Uses Trellix GTI to detect executable files that have code resembling malware.

/filestoscan

  • all

  • default

  • Comma-separated file extensions

Specifies file types to scan.

  • all — Scans all files, regardless of extension.

  • default — Scans:

    • Default list of file extensions defined in the current AMCore content file, including files with no extension.

    • File extensions already defined in the original scan. You can't add new extensions to scan with the command-line scanner.

    The scanner uses the value of the original scan to determine whether to scan known macro threats in the list of file extensions.

  • Comma-separated file extensions — Scans only files with the extensions that you specify. The scanner uses the value of the original scan to determine whether to scan files with no extension.



Examples: Custom on-demand scan command line interface

Open a command prompt and change to the installation location of amcfg.exe to run these example commands. By default, amcfg.exe is located in the C:\Program Files\McAfee\Endpoint Security\Threat Prevention folder.

To...

Run this command

Get help on the command line interface.

amcfg.exe /scan /help

List the currently defined custom on-demand scans.

amcfg.exe /scan /list

Start a custom scan with the specified ID.

amcfg.exe /scan /task scan_ID

amcfg.exe /scan /task scan_ID /action start

Change a custom scan to scan a particular folder.

amcfg.exe /scan /task scan_ID /targets "C:\Users\Documents"

Specify these settings and run the custom scan:

  • Don't scan compressed MIME-encoded files.

  • Detect unknown macro threats.

  • Scan subfolders.

  • Set the Trellix GTI sensitivity level to very high.

amcfg.exe /scan /task scan_ID /mime 0 /detectmt 1 /insidefolders 1 /gtisensitivity 5

Scan only files with .exe extensions in the user Elmo's Downloads folder.

amcfg.exe /scan /task scan_ID /filestoscan "exe" /targets "C:\Users\Elmo\Downloads"

Get status of a cloned scan task.

amcfg.exe /scan /task "Test 1_cloned" /action status