The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Threat Prevention — On-Access Scan

Prev Next

You can specify the behavior for scans that run automatically when a user reads or writes a file on the client system.

Options
Section Option Definition
ON-ACCESS SCAN Enable On-Access Scan Enables the On-Access Scan feature.

(Enabled by default)

Enable On-Access Scan on system startup Enables the On-Access Scan feature each time you start the computer.

(Enabled by default)

Specify maximum number of seconds for each file scan Limits each file scan to the specified number of seconds.

(Enabled by default)

The default value is 45 seconds.

If a scan exceeds the time limit, the scan stops cleanly and logs a message.

Scan boot sectors Examines the disk boot sector.

(Enabled by default)

Best practice: Deselect boot sector scanning when a disk contains a unique or abnormal boot sector that can't be scanned.

Scan processes on service startup and content update Rescans all processes that are currently in memory each time:
  • You re-enable on-access scans.
  • Content files are updated.
  • The Threat Prevention service starts.
  • The system starts.

(Disabled by default)

Best practice: Because some programs or executables start automatically when you start your system, deselect this option to improve system startup time.

When the on-access scanner is enabled, it always scans all processes when they are executed.

Scan trusted installers Scans MSI files (installed by msiexec.exe and signed by Trellix or Microsoft) or Windows Trusted Installer service files.

(Disabled by default)

  • Deselect this option to improve the performance of large Microsoft application installers.
  • Deselect this option to exclude trusted installers from Adaptive Threat Protection enhanced remediation.
Scan when copying between local folders Scans files when the user copies from one local folder to another.

(Disabled by default)

If this option is:

  • Enabled — Items in the destination (write) folders are scanned.
  • Disabled (default) — Items in the destination (write) folder are not scanned.

In both cases, the scanner also scans the source (read) items unless:

  • The process is trusted so that the scanner doesn't scan when it opens files.
  • The source file has been previously scanned and the result is in the scan cache.
Scan when copying from network folders and removable drives Scans files when the user copies from a network folder or removable USB drive.

(Enabled by default)

If this option is:

  • Enabled (default) — Items in the destination (write) folders are scanned.
  • Disabled — Items in the destination (write) folder are not scanned.

If Process SettingsOn network drives is enabled, the scanner always scans the source (read) items unless:

  • The process is trusted so that the scanner doesn't scan when it opens files.
  • The source file has been previously scanned and the result is in the scan cache.

Caution

Failure to select this option leaves your system vulnerable to malware attacks.

Detect suspicious email attachments Scans and detects suspicious files as they are saved to disk by these email client applications.
  • Eudora
  • Outlook
  • Outlook Express
  • The Bat!
  • Thunderbird
  • Windows Mail
  • Windows Live Mail

(Disabled by default)

This option enables aggressive email-attachment detection using heuristic signatures, which detect most executables, scripts, and .jar files by policy, rather than looking for malware.

Select this option to scan all downloads, including archives and their contents, and MIME-encoded files. Archives are scanned 2 levels deep.

Note

This option also prevents executables and scripts downloaded by email clients from running. If an email client update downloads an executable, the update might not work.

Disable read/write scan of Shadow Copy volumes for SYSTEM process Disables read/write scans of Volume Shadow Copy (VSC) volumes by SYSTEM process (PID 4) only. Threat Prevention continues to scan all other access to VSC volumes by all other processes (other than SYSTEM), based on On-Access Scan settings.

This option provides improved performance.

(Disabled by default)

Trellix GTI Enables and configures Trellix GTI settings.
Antimalware Scan Interface Enable AMSI Enables integration with Antimalware Scan Interface (AMSI).

Select this option to enhance scanning for threats in non-browser-based scripts, such as PowerShell, JavaScript, and VBScript.

(Enabled by default)

AMSI is a generic interface standard provided by Microsoft and supported on Windows 10, Windows Server 2016, and Windows 2019 systems. It allows applications and services to integrate with Threat Prevention, providing better protection against malware.

Enable Observe mode Generates AMSI scanning events (Would Block and Would Delete) and sends them to the server, but doesn't enforce actions.

(Disabled by default)

AMSI excludes most files that are excluded from on-access scans. Some scripts, such as PowerShell, are fileless and are not excluded from AMSI.

Enable AMSI Observe mode temporarily on a few systems only while tuning to evaluate the impact of AMSI scanning.

Caution

Because enabling this mode causes AMSI to generate events but not enforce actions, your systems might be vulnerable to threats.

ScriptScan Enable ScriptScan Enables scanning JavaScript and VBScript scripts in Internet Explorer to prevent unwanted scripts from executing.

(Enabled by default)

ScriptScan doesn't scan PowerShell, JavaScript, and VBScript scripts.

Caution

If ScriptScan is disabled when Internet Explorer starts and then is enabled, it doesn't detect malicious scripts in that instance of Internet Explorer. You must restart Internet Explorer after enabling ScriptScan for it to detect malicious scripts.

Exclude these URLs or partial URLs Specifies ScriptScan exclusions by URL.

Add — Adds a URL to the exclusion list.

Delete — Removes a URL from the exclusion list.

URL exclusions are case-insensitive.

URLs can't include wildcard characters. But, any URL with a string from an excluded URL is also excluded. For example, if the URL msn.com is excluded, the following URLs are also excluded:

  • http://weather.msn.com
  • http://music.msn.com
Advanced options
Section Option Definition
Threat Detection User Messaging Display the On-Access Scan window to users when a threat is detected Displays the On-Access Scan page with the specified message to client system users when a detection occurs.

(Enabled by default)

When this option is selected, users can open this page from the Scan Now page at any time the detection list includes at least one threat.

The on-access scan detection list is cleared when the Trellix ENS service restarts or the system reboots.

Message Specifies the message to display to client system users when a detection occurs.

The default message is: Trellix Endpoint Security detected a threat.

Process Settings Use Standard settings for all processes Applies the same configured settings to all processes when performing an on-access scan.
Configure different settings for High Risk and Low Risk processes Configures different scanning settings for each process type that you identify.
Standard Configures settings for processes that aren't identified as either high risk or low risk.

(Enabled by default)

High Risk Configures settings for processes that are high risk.
Low Risk Configures settings for processes that are low risk.
Add Adds a process to the High Risk or Low Risk list.

Click Add, then enter the process and select from the Risk drop-down. You can use the following when specifying the process:

  • File name
  • File path
  • File paths with wildcard characters (*) for files
  • File paths with wildcard characters (**) for multilevel directories

Note

The allowed wildcard characters while adding the process to the High Risk or Low Risk list are (?) and (*).

Delete Removes a process from the High Risk or Low Risk list.
Scanning When to scan
Let Trellix decide Allows Trellix to decide whether a file must be scanned, using trust logic to optimize scanning. Trust logic improves your security and boosts performance by avoiding unnecessary scans.

Best practice: Enable this option for the best protection and performance.

Let me decide Allows you to decide whether a file is scanned when writing to disk, when reading from disk, or both.
When writing to disk Attempts to scan all files as they are written to or changed on the computer or other data storage device.
When reading from disk Scans all files as they are read from the computer or other data storage device.
Do not scan when reading from or writing to disk Specifies to not scan Low Risk processes only.
What to scan
All files Scans all files, regardless of extension.

Caution

Failure to select this option leaves your system vulnerable to malware attacks.

Default and specified file types Scans:
  • Default list of file extensions defined in the current AMCore content file, including files with no extension
  • Any additional file extensions that you specify

    Separate extensions with a comma.

  • (Optional) Known macro threats in the list of default and specified file extensions
Specified file types only Scans either or both:
  • Only files with the (comma-separated) extensions that you specify
  • All files with no extension
On network drives Scans resources on mapped network drives.

Best practice: Deselect this option to improve performance.

Opened for backups Scans files when accessed by backup software.

Best practice: For most environments, you don't need to select this setting.

Compressed archive files Examines the contents of archive (compressed) files, including .jar files.

Best practice: Because scanning compressed archive files can negatively affect system performance, deselect this option to improve system performance.

Compressed MIME-encoded files Detects, decodes, and scans Multipurpose Internet Mail Extensions (MIME) encoded files.
Additional scan options
Detect unwanted programs Enables the scanner to detect potentially unwanted programs.

The scanner uses the information you configured in the Threat Prevention Options settings to detect potentially unwanted programs.

Detect unknown program threats Uses Trellix GTI to detect executable files that have code resembling malware.
Detect unknown macro threats Enables the scanner to detect unknown macro threats.
Actions Specifies how the scanner responds when it detects a threat.

AMSI uses the threat-detection responses specified in Actions. For example, if Threat detection first response is set to Clean files, AMSI also takes this action.

Caution

By selecting Allow access to files, your system might be vulnerable for threats.

Exclusions Specifies files, folders, and drives to exclude from scanning.

AMSI excludes most files that are excluded from on-access scans. Some scripts, such as PowerShell, are fileless and are not excluded from AMSI.

Process path or file name exclusions specified in the Standard exclusions settings are also excluded from Adaptive Threat Protection scanners.

Best practice: For information about locations to exclude from on-access scans to ensure compatibility with Microsoft technologies, see KB67211, KB51471, and KB57308

Add Adds an item to the exclusion list.
Delete Removes an item from the exclusion list.