The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Trellix GTI

Prev Next

Enable and configure Trellix GTI (Global Threat Intelligence) settings.

Options
Section Option Definition
Enable Trellix GTI Enables and disables heuristic checks.
  • When enabled, fingerprints of samples, or hashes, are submitted to Trellix Labs to determine if they are malware. By submitting hashes, detection might be made available sooner than the next AMCore content file release, when Trellix Labs publishes the update.
  • When disabled, no fingerprints or data is submitted to Trellix Labs.
Sensitivity level Configures the Trellix GTI sensitivity level to use when determining if a detected sample is malware.

The higher the sensitivity level, the higher the number of malware detections. But, allowing more detections might result in more false positive results.

Very low The detections and risk of false positives are the same as with regular AMCore content files. A detection is made available to Threat Prevention when Trellix Labs publishes it instead of in the next AMCore content file update.

Use this setting for desktops and servers with restricted user rights and strong security configurations.

Average results: 10–15 queries per day, per computer.

Low This setting is the minimum recommendation for laptops, desktops, and servers with strong security configurations.

Average results: 10–15 queries per day, per computer.

Medium Use this setting when the regular risk of exposure to malware is greater than the risk of a false positive. Trellix Labs proprietary, heuristic checks result in detections that are likely to be malware. But, some detections might result in a false positive. With this setting, Trellix Labs checks that popular applications and operating system files don't result in a false positive.

This setting is the minimum recommendation for laptops, desktops, and servers.

Average results: 20–25 queries per day, per computer.

High Use this setting for deployment to systems or areas which are regularly infected.

Average results: 20–25 queries per day, per computer.

Very high Use this setting for non-operating system volumes.

Detections found with this level are presumed malicious, but haven't been fully tested to determine if they are false positives.

Use this setting only to scan volumes and directories that don't support executing programs or operating systems.

Average results: 20–25 queries per day, per computer.