The heuristic_detections key allows you to enable and disable the heuristic detection exclusion from Trellix Endpoint Security (HX) xAgent malware protection engine's quarantine and remediation actions. Valid values are true (enabled) or false (disabled).
When the heuristic_detections exclusion is enabled, the Trellix Endpoint Security (HX) xAgent malware protection engine does not quarantine or protect the host endpoint from malware detected using heuristic detection. By default, the heuristic_detections key is disabled.
If the heuristic_detections key value is true, set the following key values to true:
malware Detection enable Key
Quarantine enable Malware Quarantine Key
Important
If these keys are not enabled, the
heuristic_detectionskey value is ignored.
Change this setting using one of the following methods:
Web UI (see Excluding Heuristic Detections from Malware Protection Processing).
API custom configuration channels (see Using API Custom Configuration Channels).
Manually on individual endpoints using a text editor (see Modifying the Configuration File for a Single Endpoint).