The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Exclude processes from Adaptive Threat Protection scanning on a client system

Prev Next

ATP scanning uses exclusions defined in the Threat Prevention On-Access Scan settings for Standard process types.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Tip

Best practice: For suggestions on how to improve Endpoint Security performance, see KB88205.

On-access scan Standard process exclusions specified by file name or file path apply to all ATP scanners, including Dynamic Application Containment and Real Protect. On-access scan exclusions specified by file type or age don't apply to ATP. ATP supports the same wildcards in path-based exclusions as Threat Prevention does.

Endpoint Security treats all file and folder exclusions as case insensitive — all case variations of the specified locations are excluded. For example, if you exclude C:\Temp\ABC, Endpoint Security also excludes C:\temp\abc and C:\TEMP\Abc.

Tip

Best practice: For information about troubleshooting blocked third-party applications, see KB88482.

For a list of executables that ATP scanned, check the Adaptive Threat Protection debug log (AdaptiveThreatProtection_Debug.log) on the client system.

Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Adaptive Threat Protection on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Threat Prevention on the Settings page.

  3. Click Show Advanced.

  4. Click On-Access Scan.

  5. In the Process Types section, select the Standard tab.

    Note

    Exclusions specified in the High Risk and Low Risk tabs don't apply to ATP.

  6. In the Exclusions section, click Add to enter the process to exclude from ATP scanning. In the When to exclude section, select When reading from disk.

    Tip

    If you want to exclude items from ATP scanning only, select this option. Threat Prevention still scans those items when they are being written to or changed on the disk.

  7. Click Apply.