If enhanced script scanning is blocking scripts that you want to allow to run, you can exclude them from scanning. These exclusions apply to both Threat Prevention and Adaptive Threat Protection.
The process for excluding items from scanning depends on the type of exclusion.
Exclusion type | Action | Where specified? |
|---|---|---|
File-based exclusion | Excludes the file from scanning. | In the Exclusions section of the Threat Prevention On-Access Scan settings for Standard process types. |
Hash-based exclusion | Excludes the hash from scanning. | In the Detection Exclusions section of the Threat Prevention Options settings for Standard process types.
|
Buffer-hash exclusion | Excludes the buffer from scanning. | In the Detection Exclusion section of the Threat Prevention Options settings. |
Command-line suppression | Scans the command line, but doesn't enforce the action specified in the Action Enforcement section of the Adaptive Threat Protection Options settings. If detections occur, ATP generates | In the Detection Exclusion section of the Threat Prevention Options settings. |
Select Menu → Reporting → Threat Event Log.
Click an event name to display its details in the Threat Event Log Details page.
AMSI scanning events include
AMSIScanin the Task Name column.From the Actions menu, select an option.
Add Buffer Exclusion
Add Command-Line Suppression
At the prompt, select the policy where you want to add the exclusion.
Trellix ePO - On-prem displays a message indicating the exclusion was added to the selected policy.
Verify that the exclusion appears in the Threat Prevention Options settings for the policy you selected.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.
From the Category list in the right pane, select Options.
Click the Edit link for the policy that you added the exclusions to.
Verify that the exclusions appear in the
Detection Exclusionlist.Buffer-hash exclusions include the prefix:
AMSI-B!Command-line suppressions include the prefix:
AMSI-CMD!