The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Exclude items from enhanced script scanning

Prev Next

If enhanced script scanning is blocking scripts that you want to allow to run, you can exclude them from scanning. These exclusions apply to both Threat Prevention and Adaptive Threat Protection.

The process for excluding items from scanning depends on the type of exclusion.

Exclusion type

Action

Where specified?

File-based exclusion

Excludes the file from scanning.

In the Exclusions section of the Threat Prevention On-Access Scan settings for Standard process types.

Hash-based exclusion

Excludes the hash from scanning.

In the Detection Exclusions section of the Threat Prevention Options settings for Standard process types.

Note

ENS supports MD5, SHA-1, and SHA-256 hashes in hexadecimal format.

Buffer-hash exclusion

Excludes the buffer from scanning.

In the Detection Exclusion section of the Threat Prevention Options settings.

Command-line suppression

Scans the command line, but doesn't enforce the action specified in the Action Enforcement section of the Adaptive Threat Protection Options settings.

If detections occur, ATP generates Would Block or Would Clean events.

In the Detection Exclusion section of the Threat Prevention Options settings.

Task
  1. Select MenuReportingThreat Event Log.

  2. Click an event name to display its details in the Threat Event Log Details page.

    AMSI scanning events include AMSIScan in the Task Name column.

  3. From the Actions menu, select an option.

    • Add Buffer Exclusion

    • Add Command-Line Suppression

  4. At the prompt, select the policy where you want to add the exclusion.

    Trellix ePO - On-prem displays a message indicating the exclusion was added to the selected policy.

  5. Verify that the exclusion appears in the Threat Prevention Options settings for the policy you selected.

    1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.

    2. From the Category list in the right pane, select Options.

    3. Click the Edit link for the policy that you added the exclusions to.

    4. Verify that the exclusions appear in the Detection Exclusion list.

      • Buffer-hash exclusions include the prefix: AMSI-B!

      • Command-line suppressions include the prefix: AMSI-CMD!