The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Prevent false positives for trusted modules on ENS Client

Prev Next

Configure ENS to exclude a specific trusted module or file from scanning without disabling the protection rule globally. This allows exclusions for AMSI, Exploit Prevention, and other detection types using the file's SHA-256 hash or name.

Note

ENS supports MD5, SHA-1, and SHA-256 hashes in hexadecimal format.

Before you begin

Before creating an exclusion, you must identify the file causing the false positive.

  1. Navigate to the debug log.

  2. Locate the detection event (AMSI, Exploit Prevention, and so on).

  3. Copy the hash value of the module or file.

Configure exclusion on ENS client

  1. Open the Trellix Endpoint Security client on the local system.

  2. From Settings, select Show Advanced.

  3. From options, locate Detection Exclusion.

  4. Select Add, then enter the hash value or detection name.

  5. Select Save.