The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Exclude processes from Adaptive Threat Protection scanning

Prev Next

ATP scanning uses exclusions defined in the Threat Prevention On-Access Scan settings for Standard process types.

If the TIE server is available, you can change the reputation of the file to a level that allows it to run, like Known Trusted, instead of creating exclusions.

Best practice: For suggestions on how to improve Endpoint Security performance, see KB88205.

On-access scan Standard process exclusions specified by file name or file path apply to all ATP scanners, including Dynamic Application Containment and ML Protect. On-access scan exclusions specified by file type or age don't apply to ATP. ATP supports the same wildcards in path-based exclusions as Threat Prevention does.

Endpoint Security treats all file and folder exclusions as case insensitive — all case variations of the specified locations are excluded. For example, if you exclude C:\Temp\ABC, Endpoint Security also excludes C:\temp\abc and C:\TEMP\Abc.

Best practice: For information about troubleshooting blocked third-party applications, see KB88482.

For a list of executables that ATP scanned, check the Adaptive Threat Protection debug log (AdaptiveThreatProtection_Debug.log) on the client system.

Task
  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane..

  2. From the Category list in the right pane, select On-Access Scan.

  3. Click the Edit link for an editable policy.

  4. Click Show Advanced.

  5. In the Process Types section, select the Standard tab.

    Note

    Exclusions specified in the High Risk and Low Risk tabs don't apply to ATP.

  6. In the Exclusions section, click Add to enter the process to exclude from ATP scanning.

    In the When to exclude section, select On read.

    Tip

    If you want to exclude items from ATP scanning only, select this option. Threat Prevention still scans those items when they are being written to or changed on the disk.