The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Responding to on-demand scan detections

Prev Next

When the on-demand scanner detects a threat, it responds based on the type of on-demand scan. For custom on-demand scans, the scanner uses Custom On-Demand Scan client task settings. For policy-based on-demand scans, the scanner uses On-Demand Scan policy settings.

Review the information in the log file to decide whether to take more actions:

  • Fine-tune items to scan.

    To make scanning more efficient, exclude legitimate files and delete known threats from the quarantine.

  • Configure the scanner to prompt for action.

  • Configure the scanner to perform actions on files.

    • Continue scanning — Continues scanning when a threat is detected.

    • Clean files — Removes the threat from the detected file, if possible.

    • Delete — Deletes the item that contains the threat.

      If an action isn't available for the current detection, the corresponding option isn't available. For example, Clean isn't available if the file has already been deleted, or Delete isn't available if the settings don't allow it.

  • Submit a sample to Trellix Advanced Research Center for analysis.

    If you find a false positive or a false negative, submit a sample of the threat to Trellix Advanced Research Center.