The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

How system utilization works

Prev Next

System utilization (throttling) determines the amount of CPU time allotted during an on-demand scan.

The on-demand scanner uses the Windows Set Priority setting for the scan process and thread priority.

Note

Each task runs independently, unaware of the limits for other tasks.

System utilization settings

System utilization setting

This option...

Best practices

Low

  • Provides improved performance for other running applications.

  • Sets the number of threads for the scan to 1.

Select this option for systems with end-user activity.

Below normal

  • Sets the number of threads for the scan to be equal to the number of CPUs.

  • Is the default setting for the preconfigured Full Scan and Quick Scan on-demand scans.

Normal

  • Enables the scan to complete faster.

  • Sets the number of threads for the scan to twice the number of CPUs.

  • Is the default setting for custom on-demand scans.

Select this option for systems that have large volumes and little end-user activity.



CPU usage during scans

You can use the Windows Task Manager to view CPU utilization consumed by the Trellix Scanner service process (mcshield.exe).

The scan process for Full Scan and Quick Scan on-demand scans runs at low priority. But, if no other processes are running during a scan, the mcshield.exe process might consume a higher amount of CPU resources. If any other processes make system requests, mcshield.exe releases the CPU resources.