Configure and manage the Anti-Malware scan settings.
Important
|
Anti-Malware proactively detects and eliminates malware threats by analyzing files,
processes,
and system activities in real time. Utilizing signature-based detection, heuristic
analysis, and
machine learning, Anti-Malware identifies known and emerging threats, including viruses,
ransomware, spyware, and trojans. Anti-Malware also automatically quarantines, deletes,
or
remediates threats based on severity, keeping systems protected without manual intervention.
Procedure
- To allow Anti-Malware to scan and protect your endpoints, select Enable.
- Configure the Monitoring level.Monitoring level is the degree of vigilance and strictness applied when detecting and responding to potential threats. Higher monitoring levels provide greater sensitivity but might generate a large number of nonessential logs and impact endpoint performance. Trend Micro recommends setting your monitoring level to 2 - Moderate for more relevant data with minimal impact on your endpoints.
- To configure the sensitivity of Anti-malware rules, set the Detection level.
- To configure the strictness of response actions, set the Prevention level.

Important
The Prevention level must be equal to or lower than the Detection level.
- To allow the agent to actively scan folders and endpoint resources commonly targeted by threats, select Enable real-time scan under Scan settings.
- To enable a regular scan of the endpoint, add a schedule to the schedule list.

Important
Anti-malware currently only supports one schedule at a time. If you need to change the schedule, click the unlink icon for (
) the current schedule, then add a new one.- To add a new schedule, click Add schedule.
- In the Select schedule window, select the schedule you configured in policy resources to use for Anti-Malware scans.
- Click Select.
- If you need to change or remove a schedule, click the Unlink icon (
) to stop using the currently selected schedule.
- To exclude certain files and directories from Anti-Malware scans, manage the Scan exclusions.

Important
You can select up to 10 of each type of list. However, selecting multiple exclusion lists is only supported by Trend Vision One Endpoint Security agent version 202601 or later.Older agent versions only support selecting one of each type of list at a time. Selecting more than one list for older agent versions might cause unwanted behavior.You can change the selected lists at any time or manage the lists in Policy Resources:You can also specify trusted programs to exclude from all security scans in Exclusions.- To manage your selected exclusion lists, click Manage exclusions.
- To exclude specified file directories, select up to 10 configured Directory lists you want to use.
- To exclude specified files, select up to 10 configured File lists you want to use.
- To exclude specified file extensions, select up to 10 configured File extension lists you want to use.
- To exclude specified hash values, select up to 10 configured Hash lists you want to use.
- Click Save.
