Configure ENS to exclude a specific trusted module or file from scanning without disabling the protection rule globally. This allows exclusions for AMSI, Exploit Prevention, and other detection types using the file's SHA-256 hash or name.
Note
ENS supports MD5, SHA-1, and SHA-256 hashes in hexadecimal format.
Before you begin
Before creating an exclusion, you must identify the file causing the false positive.
Navigate to the debug log.
Locate the detection event (AMSI, Exploit Prevention, and so on).
Copy the hash value of the module or file.
Configure exclusion on ENS client
Open the Trellix Endpoint Security client on the local system.
From Settings, select Show Advanced.
From options, locate Detection Exclusion.
Select Add, then enter the hash value or detection name.
Select Save.