The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Preventing Threat Prevention from blocking trusted programs, networks, and services

Prev Next

Threat Prevention enables you to fine-tune your protection by specifying items to exclude.

For example, you might need to exclude some file types to prevent a scanner from locking a file used by a database or server. A locked file can cause the database or server to fail or generate errors.

Best practice: To improve performance of on-access and on-demand scans, use scan avoidance techniques rather than adding file and folder exclusions.

Exclusions in exclusion lists are mutually exclusive. Each exclusion is evaluated separately from the others in the list.

Endpoint Security treats all file and folder exclusions as case insensitive — all case variations of the specified locations are excluded. For example, if you exclude C:\Temp\ABC, Trellix ENS also excludes C:\temp\abc and C:\TEMP\Abc.

Note

To exclude a folder on Windows systems, append a backslash (\) character to the path.

For this feature...

Specify items to exclude

Where to configure

Exclude items by

Use wildcards?

Access Protection

Processes (for all rules or a specified rule)

Access Protection

Process file name or path

Yes (* and ?)

MD5 hash

No

Signer

No

Exploit Prevention

Note

This feature is not supported in the ARM architecture.

Processes

Exploit Prevention

Process file name or path

Yes (* and ?)

MD5 hash

No

Signer

No

User SID

No

Group SID

No

User name

No

Group name

No

Hostname

Yes (* and ?)

Caller modules

Caller module file name or path

Yes (* and ?)

MD5 hash

No

Signer

No

APIs

API name

No

Signatures

Signature ID

No

IP addresses

IP addresses or ranges

No

Services

Service name

No

All scans

Detection names and hashes

Options

Detection name and hash

(Exact name and case, and hash value)

Yes (* and ?)

Potentially unwanted programs

Name

Yes (* and ?)

On-access scan

  • Standard

  • High Risk

  • Low Risk

Files, file types, and folders

On-Access Scan

File name or path

Yes (* and ?)

File type (extension)

Yes (*)

File age

No

ScriptScan URLs

URL name

Partial URL

No

On-demand scan

  • Quick Scan

  • Full Scan

  • Right-Click Scan

Files, folders, and drives

On-Demand Scan

File name or path

No

File Type

(Extension)

No

File age

No

Custom on-demand scan

Files, folders, and drives

  • Trellix ePO - On-premCustom On-Demand Scan client task

  • Trellix Endpoint Security (ENS) ClientTasksAdd TaskCustom scan

TasksAdd TaskCustom scan

File name or path

Yes (* and ?)

File type (extension)

Yes (*)

File age

No

Best practices: Recommended exclusions for on-access scans

Microsoft provides recommendations for locations to exclude from file-level scanners, such as the Threat Prevention on-access scanner. For information about these recommendations, see these KB articles.

To ensure compatibility with...

See this KB article

Microsoft SQL Server

KB67211

Microsoft Exchange

KB51471

Windows Domain Controller with Active Directory or File Replication Service (FRS)/Distributed File System Replication (DFSR)

KB57308