The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

ML Protect test scan result codes

Prev Next

To verify that the ML Protect scanning feature is installed and working correctly, you can schedule a scan, then check that it completed successfully. Each time ML Protect completes a scan of a file, it creates an entry in the AdaptiveThreatProtection_Activity.log file with an ID that indicates the result of the scan.

AdvancedThreatProtection_Activity.log is saved at this location by default: %ProgramData%\McAfee\Endpoint Security\Logs

ML Protect ID

Description

0

Process found with clean reputation

1

Process found with unknown reputation

2

Time out

3

Unknown failure

4

Unsupported version of ML Protect

5

Not enough events

6

Managed product request does not scan

7

Phase 1 remediation is over

8

Process terminated

9

No network detected

10

Process restarted multiple times during a short period of time and no scan was performed

11

Process is cached with unknown reputation

12

ETW session is not available

13

Multiple DLL scan requests are issued for the same process