Threat Prevention enables you to fine-tune your protection by specifying items to exclude.
For example, you might need to exclude some file types to prevent a scanner from locking a file used by a database or server. A locked file can cause the database or server to fail or generate errors.
Best practice: To improve performance of on-access and on-demand scans, use scan avoidance techniques rather than adding file and folder exclusions.
Exclusions in exclusion lists are mutually exclusive. Each exclusion is evaluated separately from the others in the list.
Trellix ENS treats all file and folder exclusions as case insensitive — all case variations of the specified locations are excluded. For example, if you exclude C:\Temp\ABC, Trellix ENS also excludes C:\temp\abc and C:\TEMP\Abc.
Note
To exclude a folder on Windows systems, append a backslash (\) character to the path.
For this feature... | Specify items to exclude | Where to configure | Exclude items by | Use wildcards? |
|---|---|---|---|---|
Access Protection | Processes (for all rules or a specified rule) | Access Protection | Process file name or path | Yes (* and ?) |
MD5 hash | No | |||
Signer | No | |||
Exploit Prevention
| Processes | Exploit Prevention | Process file name or path | Yes (* and ?) |
MD5 hash | No | |||
Signer | No | |||
User SID | No | |||
Group SID | No | |||
User name | No | |||
Group name | No | |||
Hostname | Yes (* and ?) | |||
Caller modules | Caller module file name or path | Yes (* and ?) | ||
MD5 hash | No | |||
Signer | No | |||
APIs | API name | No | ||
Signatures | Signature ID | No | ||
IP addresses | IP addresses or ranges | No | ||
Services | Service name | No | ||
All scans | Detection names and hashes | Options | Detection name and hash (Exact name and case, and hash value) | Yes (* and ?) |
Potentially unwanted programs | Name | Yes (* and ?) | ||
On-access scan
| Files, file types, and folders | On-Access Scan | File name or path | Yes (* and ?) |
File type (extension) | Yes (*) | |||
File age | No | |||
ScriptScan URLs | URL name Partial URL | No | ||
On-demand scan
| Files, folders, and drives | On-Demand Scan | File name or path | No |
File Type (Extension) | No | |||
File age | No | |||
Custom on-demand scan | Files, folders, and drives |
Tasks → Add Task → Custom scan | File name or path | Yes (* and ?) |
File type (extension) | Yes (*) | |||
File age | No |
Best practices: Recommended exclusions for on-access scans
Microsoft provides recommendations for locations to exclude from file-level scanners, such as the Threat Prevention on-access scanner. For information about these recommendations, see these KB articles.