The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Reclassify Endpoint Executable

Prev Next

You can separately classify alerts with executables hash files. You can either allow or block it. When an executable hash file is seen for the first time in the network, you have the option to unclassify it and send it for further analysis. You can later perform forensics for these hash files.

Task

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.
  2. Select the alert whose file hash you want to allow or block or unclassify.
  3. Click Other Actions, select Create Exception, and click Reclassify Endpoint Executable: <hash file>.
    A confirmation message is displayed.
  4. Click Yes.
    A successfully allowed/blocked/unclassified message is displayed.

    You can view/edit the endpoint executable file hash under Analysis → <Admin Domain Name> → Endpoint Executables.

    For more information on endpoint executable file hash, see Analyze Endpoint Executables.