The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add file hash to Allow/Block list

Prev Next

The MD5 hash value of a malware file added to the allow list is exempted from analysis as it is safe. On the other hand, the MD5 hash value of a malware file added to the block list is immediately blocked as it is malicious. You can add the file hash of a malware alert from the Attack Log.

Task

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.
  2. Select the malware whose file hash you want to allow or block.
  3. Click Other Actions, select Create Exception, and click Allow File Hash: <hash file>/Block File Hash: <hash file>.
    A confirmation message is displayed.
  4. Click Yes.
    A successfully allowed/blocked message is displayed.

    You can view/edit the allowed/blocked file hashes under Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → File Hashes.

    For more information on allowing/blocking file hashes, see the Trellix Intrusion Prevention System Product Guide.