The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Exclude items from enhanced script scanning

Prev Next

If enhanced script scanning is blocking scripts that you want to allow to run, you can exclude them from scanning or detection. These exclusions apply to both Threat Prevention and Adaptive Threat Protection.

How you exclude items from scanning, detection, or both depends on the exclusion type.

From Policy catalog
  1. Log on to ePO - On-prem , the select Menu → Policy → Policy catalog.

  2. Select Threat Prevention from the Products list in the left pane.

  3. From the Category list in the right pane, select Options.

  4. Scroll down to find Detection exclusions, then click Add.

  5. In the exclusion configuration window, you can define the following:

    Exclusion type

    Action

    File-based

    Enter the detection name.

    Excludes the file from scanning.

    Important rules for formatting your file-based exclusions:

    • Using wildcards - You can use the ? and * wildcards to represent one or more characters for file names, paths, and extensions.

    • Case insensitivity - Trellix ENS treats all file and folder exclusions as case insensitive. For example, if you exclude C:\Temp\ABC, it will automatically exclude c:\temp\abc as well.

    • Excluding folders - If your goal is to exclude an entire folder rather than a specific file, you must append a backslash (\) to the end of the folder path.

    Hash-based exclusion

    Enter the file's unique hash value.

    Excludes the hash from detection.

    Exclude by Buffer-hash

    Enter the buffer hash. The buffer hashes include the prefix: AMSI-B!

    Excludes the buffer from detection. It is used to suppress the detection from AMSI scans.

    Command-line suppression

    Enter the command-line or script that should not be blocked or cleaned if it triggers a detection. This includes the prefix: AMSI-CMD!. ENS scans the command line, but doesn't enforce the action specified in the Actions section of the On-Access Scan settings for Standard process types. If detections occur, Threat Prevention generates Would Block or Would Clean events.

    Scans the command line, but doesn't enforce the action specified in the Action Enforcement section of the Adaptive Threat Protection Options settings.

    If detections occur, ATP generates Would Block or Would Clean events.

  6. Click Save.

From Threat event log
  1. Log on to ePO - On-prem , the select Menu → Reporting → Threat Event Log.

  2. Click on an event name that includes AMSIScan in the Task Name column.

  3. From the Actions menu select:

    • Add buffer exclusion

    • Add command-line suppression

  4. At the prompt, select the specific Threat Prevention Options policy where you want to save the exclusion.

  5. ePO - On-prem displays a message confirming the exclusion was successfully added to your selected policy