The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

How ML Protect scanning monitors activity

Prev Next

The ML Protect scanner inspects suspicious files and activities on client systems to detect malicious patterns using machine-learning techniques. The scanner uses this information to detect zero-day malware.

The ML Protect technology is not supported on some Windows operating systems. See KB82761 for information.

The ML Protect scanner provides two options for performing automated analysis:

  • On the client system

  • In the cloud

Tip

Enable both client and cloud ML Protect options unless Technical Support advises you otherwise.

No personally identifiable information (PII) is sent to the cloud.

Client-based scanning

Client-based ML Protect uses machine learning on the client system to determine whether the file matches known malware. If the client system is connected to the Internet, ML Protect sends telemetry information to the cloud, but doesn't get automated analysis data from the cloud.

The client-based scanning sensitivity levels, which are based on mathematical formulas, assign "tolerance" to suspicious activity to assess whether the file matches known malware. The higher the sensitivity level, the more malware matches. But, allowing more detections might result in more false positives.

Sensitivity level

Recommended use

Low

Systems, such as servers, that rarely connect to the Internet or only to trusted websites (lower risk of infection).

This setting results in fewer false positives.

Medium

Systems that don't meet the other criteria. (Default)

High

Systems with multiple users and unfiltered network access (higher risk of infection).

This setting results in more false positives.

Client-based scanning requires Adaptive Threat Protection or TIE server connectivity unless offline scanning is enabled.

Tip

Because offline scanning might result in increased false positives, enable this option only for systems without connectivity to Trellix GTI or the TIE server.

Cloud-based scanning

Cloud-based ML Protect collects and sends file attributes and behavioral information to the machine-learning system in the cloud for malware analysis.

Cloud-based scanning requires connectivity to https://arc-ai1.trellix.com/. See KB79640

Tip

Disable cloud-based ML Protect on systems that aren't connected to the Internet.