Endpoint Security and AMCore use false positive mitigation to prevent files from being incorrectly considered a threat (or convicted). This feature is available when either Threat Prevention or Adaptive Threat Protection are installed.
Some heuristic-based reputations providers might assess reputation scores that introduce false positives, such as when the reputation of a file is above Unknown (50), but below a trusted reputation level.
When Threat Prevention detects a threat, AMCore checks the reputation of the convicted file to determine whether to suppress the conviction. If the file has the reputation of Might Be Trusted (70) or higher, false positive mitigation suppresses the conviction. Endpoint Security also uses telemetry data in AMCore Content updates, which can include information from other sources, such as Trellix GTI and Trust DATs, to further mitigate false positives.
When false positive mitigation suppresses a conviction, Threat Prevention generates a False Positive Mitigation event (34928), displays it in the Event Log in Trellix Endpoint Security (ENS) Client, and sends it to the Trellix ePO - On-prem Threat Event Log.
False positive mitigation is always enabled by default. Disabling ATP or enabling ATP Observe mode doesn't disable false positive mitigation.