When the ATP scanner blocks a file that you know is safe, you might be able to disable the Adaptive Threat Protection rule that triggered the detection.
Important
Disclaimer: This content was written in English. In the event of any differences between the English content and the translation, always refer to the English source. Some content has been translated with Google machine translation tools.
Note
You can't disable mandatory rules.
Trellix releases new ATP rules in AMCore content. For information about the latest ATP content, see the Trellix TIE and ATP Security Content Release Notes.
For information about ATP rules, including rule IDs and their corresponding rule names and descriptions, see KB82925.
Select Menu → Reporting → Threat Event Log.
Locate the rule in the Threat Event Log.
Select Actions → Choose Columns, and add these columns.
Threat Name
Rule ID
Click the Threat Name column to sort the contents.
Note the rule ID associated with the threat name.
Adaptive Threat Protection rules trigger threats that begin with "JTI/Suspect".
For example, Rule ID 4 (Use GTI file reputation to identify trusted or malicious files) triggers
JTI/Suspect.196612!d18b4dc5c6db.
Note
KB82925 includes alternative methods for identifying the rule.
(Optional) Navigate the Story Graph to see the details of events leading up to the detection.
Select Menu → Server Settings → Adaptive Threat Protection.
Click the tab that matches the rule group associated with the policy: Productivity, Balanced, or Security.
To view or change the rule group assignment for the policy, see the Rule Assignment section in the Adaptive Threat Protection Options policy.
Click the Rule ID column to sort the contents.
Locate the rule ID noted in step 4.
If the triggered rule shows False in the Mandatory column, you can disable it or set it to report only.
Click Edit in the bottom right.
Select the rule checkbox.
Select Actions → Set Rule(s) to Disabled or Set Rule(s) to Observe.
Click Save.