Based on the investigation analysis if the threat is non-malicious, you can use the Configuration page to exclude the particular threat from the potential threat list.
Log on to Trellix EDR.
Click the configuration icon on the top-right corner to access the Configuration page.
Select Manage threat exclusions under Finetune configuration.
Click + Add to add a threat to the threat exclusions list and manually enter details as needed. Click Save.
Note
Make sure to select at least one criteria checkbox and add valid details, and add Threat Exclusions name. Multiple criteria are combined using the AND logical operator.
The maximum length of characters supported in each criterion:
SHA-256 — 64
File Path — 256
Command Line — 8191
For details about using wildcards in threat exclusion criteria File Path and Command Line, see the Trellix Knowledge Base article, Supported use of wildcards in Granular Exclusion for Trellix EDR - KB94998.
Examples for adding File Path and Command Line:
File Path —
c:\users\cdaauto\powershell.exeCommand Line —
c:\users\cdaauto\powershell.exe -o -s
On the Action History dashboard, Action Status displays the excluded threat action as Completed.
The list of excluded threats in Manage threat exclusions do not appear on the Monitoring dashboard.