Configure hash based exclusions to suppress the detections as detailed in the table below.
Log on to ePO - On-prem , the select Menu → Policy → Policy catalog.
Select Threat Prevention from the Products list in the left pane.
From the Category list in the right pane, select Options.
Scroll down to find Detection exclusions, then click Add.
In the exclusion configuration window, you can define the following:
Exclusion type
Action
File-based
Enter the detection name.
Important rules for formatting your file-based exclusions:
Using wildcards - You can use the ? and * wildcards to represent one or more characters for file names, paths, and extensions.
Case insensitivity - Trellix ENS treats all file and folder exclusions as case insensitive. For example, if you exclude C:\Temp\ABC, it will automatically exclude c:\temp\abc as well.
Excluding folders - If your goal is to exclude an entire folder rather than a specific file, you must append a backslash (\) to the end of the folder path.
Hash-based exclusion
Enter the file's unique hash value.
Exclude by Buffer-hash
Enter the buffer hash. The buffer hashes include the prefix:
AMSI-B!Command-line suppression
Enter the command-line or script that should not be blocked or cleaned if it triggers a detection. This includes the prefix:
AMSI-CMD!. ENS scans the command line, but doesn't enforce the action specified in the Actions section of the On-Access Scan settings for Standard process types. If detections occur, Threat Prevention generates Would Block or Would Clean events.Click Save.
Log on to ePO - On-prem , the select Menu → Reporting → Threat Event Log.
Click on an event name that includes AMSIScan in the Task Name column.
From the Actions menu select:
Add buffer exclusion
Add command-line suppression
At the prompt, select the specific Threat Prevention Options policy where you want to save the exclusion.
ePO - On-prem displays a message confirming the exclusion was successfully added to your selected policy