The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Exclude files or directories from scanning

Prev Next

Exclude files or directories from on-access scanning and on-demand scanning.

  1. Log on to the ePO - On-prem server as an administrator.

  2. From the Policy Catalog, select Endpoint Security Threat Prevention as the product, then select On-Access Scan or On-Demand Scan as required.

  3. Click the policy, then click Show Advanced.

    If you haven't created a policy, click New Policy, type a name for the policy, then click OK.

  4. In the Exclusion area under Process Settings, click Add and define these settings as required, then click Save.

    In...

    Configure...

    What to exclude

    • Pattern (can include wildcards * or ?) — Specifies the file pattern to exclude.

      For example, to exclude all files in the desktop from scanning, specify the path as /Users/user/Desktop/*

    • Also exclude subfolders — Excludes files and directories from the specified location.

    • File type (can include wildcard ?) — Excludes files that contain the extension.

    • File Age — Excludes files based on their age in terms of creation date and modified date.

      • Modified — Excludes files that were edited earlier to the days specified in the Minimum age in days field.

      • Created — Excludes files that were created earlier to the days specified in the Minimum age in days field.

      • Accessed — (On-Demand Scan only) Excludes files that were accessed earlier to the days specified in the Minimum age in days field.

    Select Overwrite exclusions configured on the client (On-Access Scan only) to overwrite the client exclusion list.

    When to exclude

    • On read — (On-Access Scan only) Excludes from scanning when the file is accessed.

    • On write — (On-Access Scan only) Excludes from scanning when the file is changed.