Users with Admin or API Admin authorization can initiate malware scans on their host endpoints. Malware scans are configured as either a Full Scan or Custom Scan. A Full Scan includes all local and mounted disk drives, while a Custom Scan gives you the option of specifying folder names or file paths. You can trigger these scans by creating and assigning a client task in the ePO console.
Prerequisites
Before you create a scan task, ensure that you have enabled the required scan options in the Malware Detection Options section of your Protection policy. For details, see Protection policy.
To create and assign a malware scan:
In the ePO console, navigate to Menu → Client Tasks → Client Task Catalog.
In the Client Task Types pane, select Trellix EDR with Forensics.
Click New Task or select an existing task to edit.
In the New Task dialog box, select the Task Types from the drop-down menu.
Custom On-Demand Scan: Select this option to define unique scan parameters such as specific file paths, drives, or exclusions within the task.
Policy Based On-Demand Scan: Select this option to run a scan that strictly inherits the predefined settings configured in your active Protection policy.
Click OK.
Type a name and description for the client task.
In the Scan Type section, select one of the following options to define the scope of the scan:
Full Scan: Scans all files, folders, and local drives on the endpoint.
Quick Scan: Scans critical system areas, the registry, and common malware hiding locations.
Active Memory: Scans only the system memory and currently running processes to detect active or fileless threats.
Click Save.
Navigate to the System Tree or Client Task Assignments page to assign the task to your target endpoints, and set the schedule to run immediately or at a designated time.