The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Adaptive Threat Protection — Dynamic Application Containment

Prev Next

Protect your system by limiting the actions that contained applications can perform based on configured rules.

Options
Section Option Description
Containment Rules Configures Dynamic Application Containment rules.

You can change whether Trellix-defined containment rules block or report, but you can't otherwise change or delete these rules.

  • Block (only) — Blocks, without logging, contained applications from performing actions specified by the rule.
  • Report (only) — Logs when applications try to perform actions in the rule, but doesn't prevent applications from performing actions.
  • Block and Report — Blocks and logs access attempts.

To block or report all, select Block or Report in the first row.

To disable the rule, deselect both Block and Report.

Contained Applications Lists applications that are currently contained.
  • Exclude — Moves a contained application to the Exclusions list, releasing it from containment and allowing it to run normally.
Advanced options
Section Option Description
Exclusions Excludes processes from containment.
  • Add — Adds a process to the exclusion list.
  • Double-click an itemChanges the selected item.
  • DeleteDeletes the selected item.
  • DuplicateCreates a copy of the selected item.