The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

How Trellix GTI works

Prev Next

Trellix GTI uses heuristics or file reputation to check for suspicious files through on-access scanning and on-demand scanning.

The scanner submits fingerprints of samples, or hashes, to a central database server hosted by Trellix Advanced Research Center to determine if they are malware. By submitting hashes, detection might be made available sooner than when Trellix Advanced Research Center publishes the next content file update.

You can configure the sensitivity level that Trellix GTI uses when it determines if a detected sample is malware. The higher the sensitivity level, the higher the number of malware detections. But, allowing more detections can result in more false positives. The Trellix GTI sensitivity level is set to Medium by default. Configure the sensitivity level for each scanner in the On-Access Scan and On-Demand Scan settings.

You can configure Trellix ENS to use a proxy server for retrieving Trellix GTI reputation information in the Common settings.

For frequently asked questions about Trellix GTI, see KB53735.