The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Queries, reports, and Threat Prevention

Prev Next

Use queries to retrieve detailed information about the status of your managed systems and any threats in your environment. You can export, download, or combine queries into reports, and use queries as dashboard monitors.

Queries are questions that you ask ePO - On-prem., which returns answers as charts and tables. Reports enable you to package one or more queries into a single PDF document, for access outside of ePO - On-prem.

Similar information is available by accessing activity logs from the Trellix Endpoint Security (ENS) Client on individual systems.

You can view query data only for resources where you have permissions. For example, if your permissions grant access to a specific System Tree location, your queries return data only for that location.

Tip

Best practice: For information on how to create a report of which computers have an Extra.DAT file installed, see KB59410. For information on how to create a report for completed on-demand scans (event 1203), see KB69428.

Default queries

The module adds default queries to Trellix Groups. Depending on your permissions, you can use them as is, modify them, or create custom queries from events and properties in the ePO - On-prem database.

  • Endpoint Security Threat Prevention: Access Protection Compliance Status

  • Endpoint Security Threat Prevention: AMCore Content Compliance Status

  • Endpoint Security Threat Prevention: Applications with the Most Exploits in the Last 7 Days

  • Endpoint Security Threat Prevention: Content Status

  • Endpoint Security Threat Prevention: Detection Response Summary

  • Endpoint Security Threat Prevention: Duration of Completed Full Scans in the Last 7 Days

  • Endpoint Security Threat Prevention: Duration of Completed Quick Scans in the Last 7 Days

  • Endpoint Security Threat Prevention: Exploit Prevention Compliance Status

  • Endpoint Security Threat Prevention: Exploit Prevention Content Status

  • Endpoint Security Threat Prevention: False Positive Mitigation Events

  • Endpoint Security Threat Prevention: Hotfixes Installed

  • Endpoint Security Threat Prevention: On-Access Scan Compliance Status

  • Endpoint Security Threat Prevention: On-Access Scan McAfee GTI Sensitivity Level

  • Endpoint Security Threat Prevention: On-Demand Full Scan McAfee GTI Sensitivity Level

  • Endpoint Security Threat Prevention: On-Demand Quick Scan McAfee GTI Sensitivity Level

  • Endpoint Security Threat Prevention: Right-Click Scan McAfee GTI Sensitivity Level

  • Endpoint Security Threat Prevention: Systems Not Completed a Full Scan in the Last 7 Days

  • Endpoint Security Threat Prevention: Systems Not Completed a Full Scan in the Last Month

  • Endpoint Security Threat Prevention: Threat Count by Severity

  • Endpoint Security Threat Prevention: Threats Detected Over the Previous 2 Quarters

  • Endpoint Security Threat Prevention: Top 10 Access Protection Rules Broken

  • Endpoint Security Threat Prevention: Top 10 Computers with the Most Detections

  • Endpoint Security Threat Prevention: Top 10 Detected Threats

  • Endpoint Security Threat Prevention: Top 10 Exploits Prevented

  • Endpoint Security Threat Prevention: Top 10 Threat Sources

  • Endpoint Security Threat Prevention: Top 10 Threats per Threat Category

  • Endpoint Security Threat Prevention: Top 10 Users with the Most Detections

Custom queries (ePO - On-prem)

The module adds default properties to the Endpoint Security feature group. You can use these properties to create custom queries.

Feature Group

Result Type

Property (Column)

Property (Column)

Endpoint Security

Endpoint Security ePO - On-prem Systems

Access Protection Additional Reasons

License Status

Access Protection Compliance Status

Names of threats that Extra.DAT can detect

Access Protection Enabled

On-Access Scan Additional Reason

Access Protection Reason

On-Access Scan Compliance Status

AMCore Content Additional Reasons

On-Access Scan Enabled

AMCore Content Compliance Days

On-Access Scan Threat Prevention Sensitivity

AMCore Content Compliance Status

On-Access Scan Reason

AMCore Content Date

On-Demand Full Scan Date

AMCore Content Reason

On-Demand Full Scan Duration (hours)

AMCore Content Version

On-Demand Full Scan Threat Prevention Sensitivity

AMCore Engine Version

On-Demand Quick Scan Date

AMSI Enabled

(Windows 10 and Windows Server 2016 systems only)

On-Demand Quick Scan Duration (minutes)

AMSI Observe Mode Enabled

(Windows 10 and Windows Server 2016 systems only)

On-Demand Quick Scan Threat Prevention Sensitivity

AMSI supported by system

On-Demand Scan Additional Reasons

AMSI supported by system reason

On-Demand Scan Compliance Status[a]

DAT Version (Non-Windows)

On-Demand Scan Reason

Exploit Prevention Additional Reasons

Right-Click Scan Trellix Sensitivity

Exploit Prevention Compliance Status

ScriptScan Additional Reasons

Exploit Prevention Content Created

ScriptScan Compliance Status

Exploit Prevention Content Version

ScriptScan Enabled

Exploit Prevention Enabled

ScriptScan Reason

Exploit Prevention Reason

Threat Prevention Hotfix

Language

Threat Prevention Patch Version

Endpoint Security Platform Systems

Access Protection Debug Logging Enabled

On Access Scan Debug Logging Enabled

Access Protection Events Filter Level

On Access Scan Events Filter Level

Exploit Prevention Debug Logging Enabled

On Demand Scan Debug Logging Enabled

Exploit Prevention Events Filter Level

On Demand Scan Events Filter Level

Events

Exploit Prevention Events

Access Requested

Source Port

Action Taken

Source Process Hash

Agent GUID

Source Process Signed

AMCore Content Version

Source Process Signer

Analyzer Content Creation Date

Source Share Name

Analyzer Content Creation Version

Source Signed

Analyzer Detection Method

Source Signer

Analyzer Trellix Query

Source URL Rating Code

Analyzer Reg Info

Source URL Web Category

Analyzer Rule ID

Target Access Time

Analyzer Rule Name

Target Create Time

Analyzer Technology Version

Target Description

API Name

Target Device Display Name

Attack Vector Type

Target Device PID

Cleanable

Target Device Serial Number

DAT Version

Target Device VID

Description

Target File Size (Bytes)

Detecting Prod ID (deprecated)

Target Hash

Detecting Product Host Name

Target Modify Time

Detecting Product IP Address

Target Name

Detecting Product IPv4 Address

Target Parent Process Hash

Detecting Product MAC Address

Target Parent Process Name

Detecting Product Name

Target Parent Process Signed

Detecting Product Version

Target Parent Process Signer

Direction

Target Path

Duration Before Detection (Days)

Target Share Name

Engine Version

Target Signed

Event Category

Target Signer

Event Generated Time

Target URL

Event ID

Task Name

Event Received Time

Threat Detected On Creation

First Action Status

Threat Handled

First Attempted Action

Threat Impact

Location

Threat Name

Module Name

Threat Severity

Second Action Status

Threat Source Host Name

Second Attempted Action

Threat Source IP Address

Server ID

Threat Source IPv4 Address

Source Access Time

Threat Source MAC Address

Source Create Time

Threat Source Process Name

Source Description

Threat Source URL

Source Device Display Name

Threat Source User Name

Source Device PID

Threat Target File Path

Source Device Serial Number

Threat Target Host Name

Source Device VID

Threat Target IP Address

Source File Hash

Threat Target IPv4 Address

Source File Path

Threat Target MAC Address

Source File Size (Bytes)

Threat Target Network Protocol

Source Modify Time

Threat Target Port Number

Source Parent Process Hash

Threat Target Process Name

Source Parent Process Name

Threat Target User Name

Source Parent Process Signed

Threat Type

Source Parent Process Signer

Topic

[a] For information about queries and reports, see the Trellix ePO - On-prem documentation.

A system is considered compliant for on-demand scans based on any of the following criteria:

  • Threat Prevention was installed less than 7 days ago.

  • The on-demand scan Full Scan task completed less than 7 days ago.

  • An on-demand scan task that at least contains all same scan locations as the Full Scan task, completed less than 7 days ago.