Configure file-based exclusions to exclude a specific trusted module or file from scanning without disabling the protection rule globally.
Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.
Open the Trellix Endpoint Security (ENS) Client .
Click Threat Prevention on the main Status page.
Or, from the Action menu
, select Settings, then click Threat Prevention on the Settings page.Click Show Advanced.
From the Threat Prevention options policy, locate Detection Exclusion.
Select Add, for each On-Access Scan type, select one of the follwoing:
Hash-based exclusion - Excludes the hash from detection.
Buffer-hash exclusion - Excludes the hash from detection. The buffer hashes include the prefix
AMSI-B!.Command-line suppression - Scans the command line, but doesn't enforce the action specified in the Actions section of the On-Access Scan settings for Standard process types. If detections occur, Threat Prevention generates
Would BlockorWould Cleanevents. It is used to suppress the detection from AMSI scans. It includes the prefixAMSI-CMD!.
Under Actions, configure responses to unwanted programs.