You can edit the list of existing threats that are excluded from the threat list and add new threats to the exclusion list. The excluded threats do not appear on the Monitoring dashboard.
Note
The maximum number of threats that can be excluded from showing on the Monitoring dashboard is 1500. We recommend you avoid creating threat exclusions, except in specific cases, because they can result in missed detections.
Log on to Trellix EDR.
Click the configuration icon on the top-right corner to access the Configuration page.
Select Manage threat exclusions under Finetune configuration to see the list of excluded threats.
Select a threat from the excluded threat list and edit as needed.
Enable or disable criteria such as SHA-256, File Path (includes shared network path), and Command Line.
(Optional) Edit any of the existing criteria, Threat Exclusions name, or Note details. Click Save.
Important
Multiple criteria are combined using the AND logical operator.
A new threat exclusion row is created with edited details.
For details about using wildcards in threat exclusion criteria File Path and Command Line, see the Trellix Knowledge Base article, Supported use of wildcards in Granular Exclusion for Trellix EDR - KB94998.
Click Delete to delete a threat from the existing threat exclusions list. The threat deleted from the threat exclusions list is shown on the Monitoring dashboard.
Click + Add to add a threat to the threat exclusions list and enter details as needed. Click Save.
Note
Make sure to select at least one criteria checkbox, provide valid details, and specify a name for the threat exclusion. Multiple criteria are combined using the AND operator.
The maximum length of characters supported in each criteria:
SHA-256 — 64
File Path — 256
Command Line — 8191
Examples for adding File Path and Command Line:
File Path —
c:\users\cdaauto\powershell.exeCommand Line —
c:\users\cdaauto\powershell.exe -o -s
The list of excluded threats in Manage threat exclusions do not appear on the Monitoring dashboard.