The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Prevent false positives for trusted modules on ENS Client

Prev Next

Configure ENS to exclude a specific trusted module or file from scanning without disabling the protection rule globally. This allows exclusions for AMSI, Exploit Prevention, and other detection types using the file's SHA-256 hash or name.

Note

ENS supports MD5, SHA-1, and SHA-256 hashes in hexadecimal format.

Before you begin

Before creating an exclusion, you must identify the file causing the false positive.

  1. Navigate to the debug log.

  2. Locate the detection event (AMSI, Exploit Prevention, and so on).

  3. Copy the hash value of the module or file.

Configure exclusion on ENS client

  1. Open the Trellix Endpoint Security client on the local system.

  2. From Settings, select Show Advanced.

  3. From options, locate Detection Exclusion.

  4. Select Add, then enter the hash value or detection name.

  5. Select Save.