The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Test ML Protect scanning

Prev Next

You can verify that ML Protect scanning features are installed correctly and that systems can communicate with Trellix cloud for detections.

Before you begin
  • On endpoints managed with Trellix ePO - On-prem and Trellix ePolicy Orchestrator - SaaS— Verify that ML Protect can connect to Trellix GTI or the TIE server to send queries to the domain: https://arc-ai1.trellix.com/.

  • On unmanaged endpoints — Verify that ML Protect can connect to Trellix GTI to send queries to the domain: https://arc-ai1.trellix.com/.

This test uses password-protected files to check ML Protect client-based and cloud-based detections. Although they are designed to be detected as threats, they are harmless.

You need to download the test files to a different location each time you run this test. ML Protect does not detect the files on subsequent attempts to run them from the same location.

Task
  1. Make sure that Endpoint Security and Adaptive Threat Protection are running.

  2. On the client system, download the compressed test file from this location: KB88828.

  3. Navigate to the folder where you downloaded the file, then unzip the file.

    The password for the .zip file is clean. Password protection ensures that the .zip file is not blocked if you send it in an email.

  4. To test client detections, double-click RP-S TestFile.exe.

    If ML Protect client scanning is functioning correctly in Endpoint Security, it detects the file and prevents the file from running.

  5. To test cloud detections:

    Caution

    Don't disable the Clean when reputation threshold reaches option. If you disable this option, all active process detection including ML Protect cloud-based detection will not occur.

    1. In the Adaptive Threat Protection Options policy, under Action Enforcement, enable Clean when reputation threshold reaches. This option must be enabled for a Threat Event for RP-D to be generated on the endpoint.

    2. Double-click RP-D TestFile.exe.

    The RP-D TestFile.exe must run for a minute for the detection to trigger.

    If ML Protect cloud scanning is functioning correctly in Endpoint Security, it detects the file and prevents the file from running.

If ML Protect does not detect the file and prevent it from running, check the Adaptive Threat Protection Activity log file and troubleshoot the problem, then run the test again. AdvancedThreatProtection_Activity.log is saved at this location by default: %ProgramData%\McAfee\Endpoint Security\Logs.