The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Exclude items from scanning and detection using Trellix ePO - On-prem

Prev Next

Configure hash based exclusions to suppress the detections as detailed in the table below.

From Policy catalog
  1. Log on to ePO - On-prem , the select MenuPolicyPolicy catalog.

  2. Select Threat Prevention from the Products list in the left pane.

  3. From the Category list in the right pane, select Options.

  4. Scroll down to find Detection exclusions, then click Add.

  5. In the exclusion configuration window, you can define the following:

    Exclusion type

    Action

    File-based

    Enter the detection name.

    Important rules for formatting your file-based exclusions:

    • Using wildcards - You can use the ? and * wildcards to represent one or more characters for file names, paths, and extensions.

    • Case insensitivity - Trellix ENS treats all file and folder exclusions as case insensitive. For example, if you exclude C:\Temp\ABC, it will automatically exclude c:\temp\abc as well.

    • Excluding folders - If your goal is to exclude an entire folder rather than a specific file, you must append a backslash (\) to the end of the folder path.

    Hash-based exclusion

    Enter the file's unique hash value.

    Exclude by Buffer-hash

    Enter the buffer hash. The buffer hashes include the prefix: AMSI-B!

    Command-line suppression

    Enter the command-line or script that should not be blocked or cleaned if it triggers a detection. This includes the prefix: AMSI-CMD!. ENS scans the command line, but doesn't enforce the action specified in the Actions section of the On-Access Scan settings for Standard process types. If detections occur, Threat Prevention generates Would Block or Would Clean events.

  6. Click Save.

From Threat event log
  1. Log on to ePO - On-prem , the select MenuReportingThreat Event Log.

  2. Click on an event name that includes AMSIScan in the Task Name column.

  3. From the Actions menu select:

    • Add buffer exclusion

    • Add command-line suppression

  4. At the prompt, select the specific Threat Prevention Options policy where you want to save the exclusion.

  5. ePO - On-prem displays a message confirming the exclusion was successfully added to your selected policy