The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

How AMSI integration with Threat Prevention improves security

Prev Next

You can enable integration with Antimalware Scan Interface (AMSI) to provide protection against non-browser-based scripts, such as PowerShell, JavaScript, and VBScript. With this feature enabled, AMSI blocks the script before execution.

AMSI is a generic interface standard provided by Microsoft and supported on Windows 10, Windows Server 2016, and Windows 2019 systems. It allows applications and services to integrate with Threat Prevention, providing better protection against malware.

Tip

Best practice: For the best protection against script-based threats, enable this option with ScriptScan, which scans browser-based scripts, and Adaptive Threat Protection enhanced scanning.

Actions and Exclusions

AMSI scanning uses the Actions and Exclusions specified for Standard process types in the Process Settings section of the On-Access Scan settings.

AMSI uses the threat detection responses specified in the Actions settings. For example, if Threat detection first response is set to Clean files, AMSI also takes this action.

AMSI excludes most files that are excluded from on-access scans. Some scripts, such as PowerShell, are fileless and are not excluded from AMSI.

Identify the module causing AMSI detections

AMSI detection events now include Detection Context and Detected Module details. This information helps you identify the specific third-party module (DLL) or script responsible for the alert. If a legitimate third-party application triggers a false positive, you can use the provided module hash to create a precise suppression rule, eliminating the need to wait for a content update.