Adaptive Threat Protection — Dynamic Application Containment Published on Sep 13, 2026
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next Protect your system by limiting the actions that contained applications can perform based on configured rules.
Options
Section
Option
Description
Containment Rules
Configures Dynamic Application Containment rules.
You can change whether
Trellix -defined containment rules block or report, but you can't otherwise change or delete these rules.
Block (only) — Blocks, without logging, contained applications from performing actions specified by the rule.
Report (only) — Logs when applications try to perform actions in the rule, but doesn't prevent applications from performing actions.
Block and
Report — Blocks and logs access attempts.
To block or report all, select
Block or
Report in the first row.
To disable the rule, deselect both
Block and
Report .
Contained Applications
Lists applications that are currently contained.
Exclude — Moves a contained application to the
Exclusions list, releasing it from containment and allowing it to run normally.
Advanced options
Section
Option
Description
Exclusions
Excludes processes from containment.
Add — Adds a process to the exclusion list.
Double-click an item —
Changes the selected item.
Delete —
Deletes the selected item.
Duplicate —
Creates a copy of the selected item.
Was this article helpful?
Yes No