The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Disable a rule that triggered a detection for a known safe file

Prev Next

When the ATP scanner blocks a file that you know is safe, you might be able to disable the Adaptive Threat Protection rule that triggered the detection.

Important

Disclaimer: This content was written in English. In the event of any differences between the English content and the translation, always refer to the English source. Some content has been translated with Google machine translation tools.

Note

You can't disable mandatory rules.

Trellix releases new ATP rules in AMCore content. For information about the latest ATP content, see the Trellix TIE and ATP Security Content Release Notes.

For information about ATP rules, including rule IDs and their corresponding rule names and descriptions, see KB82925.

Task
  1. Select MenuReportingThreat Event Log.

  2. Locate the rule in the Threat Event Log.

    1. Select ActionsChoose Columns, and add these columns.

      • Threat Name

      • Rule ID

    2. Click the Threat Name column to sort the contents.

    3. Note the rule ID associated with the threat name.

      Adaptive Threat Protection rules trigger threats that begin with "JTI/Suspect".

      For example, Rule ID 4 (Use GTI file reputation to identify trusted or malicious files) triggers JTI/Suspect.196612!d18b4dc5c6db.

    Note

    KB82925 includes alternative methods for identifying the rule.

  3. (Optional) Navigate the Story Graph to see the details of events leading up to the detection.

  4. Select MenuServer SettingsAdaptive Threat Protection.

  5. Click the tab that matches the rule group associated with the policy: Productivity, Balanced, or Security.

    To view or change the rule group assignment for the policy, see the Rule Assignment section in the Adaptive Threat Protection Options policy.

  6. Click the Rule ID column to sort the contents.

  7. Locate the rule ID noted in step 4.

  8. If the triggered rule shows False in the Mandatory column, you can disable it or set it to report only.

    1. Click Edit in the bottom right.

    2. Select the rule checkbox.

    3. Select ActionsSet Rule(s) to Disabled or Set Rule(s) to Observe.

    4. Click Save.