Exclude threats using the Monitoring dashboard

Prev Next

Based on the investigation analysis if the threat is non-malicious, you can use the Monitoring dashboard to exclude the particular threat from the potential threat list.

  1. Log on to Trellix EDR.

  2. Select MenuMonitoring.

  3. On the Threats by Ranking / Threats by Time pane, select a threat to exclude it from the potential threat list.

  4. Select the Exclude from threats option from the Take Action menu.

    The Exclude from threats window appears.

  5. Exclude a threat based on SHA-256, File path (includes shared network path), and Command line criteria details. The criteria details are auto-filled.

    Important

    The SHA-256 criterion is enabled by default. Multiple criteria are combined using the "AND" logical operator.

    The File path and Command line criteria details are populated when the data is loaded on Process Activity.

    You can select Dismiss this threat option to remove this particular threat from the Monitoring dashboard.

  6. Click Confirm to complete the exclusion of threat action.

  7. On the Action History dashboard, Action Status displays the excluded threat action as Completed.

The excluded threats from the Monitoring dashboard are added to Manage threat exclusions on the Configuration page.