The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Exclude items from detection in Trellix Endpoint Security (ENS) Client

Prev Next

Configure file-based exclusions to exclude a specific trusted module or file from scanning without disabling the protection rule globally.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client .

  2. Click Threat Prevention on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Threat Prevention on the Settings page.

  3. Click Show Advanced.

  4. From the Threat Prevention options policy, locate Detection Exclusion.

  5. Select Add, for each On-Access Scan type, select one of the follwoing:

    • Hash-based exclusion - Excludes the hash from detection.

    • Buffer-hash exclusion - Excludes the hash from detection. The buffer hashes include the prefix AMSI-B!.

    • Command-line suppression - Scans the command line, but doesn't enforce the action specified in the Actions section of the On-Access Scan settings for Standard process types. If detections occur, Threat Prevention generates Would Block or Would Clean events. It is used to suppress the detection from AMSI scans. It includes the prefix AMSI-CMD!.

  6. Under Actions, configure responses to unwanted programs.