The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

View and respond to threats detected on a client system

Prev Next

Depending on how settings are configured, you can respond to threat detections from Trellix Endpoint Security (ENS) Client.

Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Scan Now to open the Scan System page.

  3. From On-Access Scan, click View Detections.

    Note

    This option isn't available if the list contains no detections or the user messaging option is disabled.

    The on-access scan detection list is cleared when the Endpoint Security service restarts or the system reboots.

  4. From the On-Access Scan page, select one of these options.

    Clean

    Attempts to clean the item (file, registry entry) and place it in the Quarantine.

    Note

    Endpoint Security uses information in the content files to clean files. If the content file has no cleaner or the file has been damaged beyond repair, the scanner and denies access to it. In this case, Trellix recommends that you delete the file from the Quarantine and restore it from a clean backup copy.

    Delete

    Deletes the item that contains the threat.

    Remove Entry

    Removes the entry from the detection list.

    Close

    Closes the scan page.

    Note

    If an action isn't available for the threat, the corresponding option is disabled. For example, Clean isn't available if the file has already been deleted.

    The on-access scan detection list is cleared when the Endpoint Security service restarts or the system reboots.