The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Using trusted executables and applications to reduce false positives

Prev Next

Trusted executables are executables that have no known vulnerabilities and are considered safe. Firewall allows network traffic initiated from trusted executables.

Configuring a trusted executable creates a bi-directional Allow rule for that executable at the top of the Firewall rules list.

Note

Firewall treats all files and folder names in rules as case insensitive. For example, if the path for a trusted executable is C:\Temp\FTP.exe, Firewall also allows C:\temp\ftp.exe and c:\TEMP\FTP.EXE.

Maintaining a list of safe executables for a system reduces or eliminates most false positives. For example, when you run a backup application, many false positive events might be triggered. To avoid triggering false positives, make the backup application a trusted executable.

Note

A trusted executable is susceptible to common vulnerabilities, such as buffer overflow and illegal use. So, Firewall still monitors trusted executables and triggers events to prevent exploits.

The Firewall Catalog contains executables and applications. Executables in the catalog can be associated with a container application. You can add executables and applications from the catalog to your list of trusted executables. Once defined, you can reference the executables in rules and groups.