You can configure the settings that apply to the Threat Prevention feature, including quarantine, potentially unwanted programs, and exclusions.
| Section | Option | Definition |
|---|---|---|
| Quarantine Manager | Quarantine folder | Specifies the location for the quarantine folder or accepts the default location:
c:\Quarantine The quarantine folder is limited to 190 characters. |
| Specify the maximum number of days to keep quarantine data | Specifies the number of days (1–999) to keep the quarantined items before automatically deleting. The default is 30 days. | |
| Exclusion by Detection Name | Exclude these detection names | Specifies exclusions by detection name for the on-access scanner, on-demand scanner, and AMSI scanner.
The detection name appears in the Threat Name column in the Trellix ePO - On-prem Threat Event Log and in Endpoint Security Client:
For example, to specify that the scanners not detect Installation Check threats, enter Installation Check. Detection name exclusions don't support wildcards.
|
| Potentially Unwanted Program Detections | Exclude custom unwanted programs | Specifies individual files or programs to treat as potentially unwanted programs.
The scanner doesn't detect a zero-byte sized user-defined unwanted program.
|
| Section | Option | Definition |
|---|---|---|
| Proactive Data Analysis | Sends anonymous diagnostic and usage data to Trellix. | |
| Trellix GTI feedback | Enables Trellix GTI -based telemetry feedback to collect anonymized data on files and processes executing on the client system. | |
| Safety Pulse | Performs a health check on the client system before and after AMCore content file updates, and at regular intervals, and sends results to
Trellix.
The results are encrypted and sent to Trellix using SSL. Trellix then aggregates and analyzes the data from these reports to identify anomalies that might indicate potential content-related issues. Prompt identification of such issues is critical to providing timely containment and remediation.
Safety Pulse collects the following types of data:
|
|
| AMCore Content Reputation | Performs a
Trellix GTI
lookup to request the reputation of an AMCore content file before updating the client system.
If the AMCore content file is classified as "block", Trellix ENS doesn't update AMCore content on the client system. |