These steps inform the endpoints on the local systems to download the agent module and install it during a configuration update. To enable the module, see Configuring the AMSI module.
After installation, the AMSI module creates an instance of Trellix xagt.exe with AMSI in its command line. This is a container application to interact with agent services. The process runs under the system account like any other agent instance.
AMSI module registers FeAmsiProvider.dll as a Trellix AMSI provider with Windows OS. The Trellix AmsiProxy.dll library is loaded into PowerShell with other runtime libraries and scripting processes that support AMSI.