You can configure settings for the Adaptive Threat Protection module, including ML Protect scanner behavior, enhanced script scanning, and the rule groups to use for calculating reputations.
| Section | Option | Definition |
|---|---|---|
| Options | Enable Adaptive Threat Protection | Enables the
Adaptive Threat Protection module.
(Enabled by default) |
| Enable Observe mode | Generates
Adaptive Threat Protection events (Would Block,
Would Clean, or
Would Contain) and sends them to the server, but doesn't enforce actions.
(Disabled by default) Enable Observe mode temporarily on a few systems only while tuning Adaptive Threat Protection. Observe mode applies to all Adaptive Threat Protection features, including ML Protect and Dynamic Application Containment.
|
|
| Allow the Threat Intelligence Exchange server to collect anonymous diagnostic and usage data | Allows the
TIE server to send anonymous file information to
Trellix.
(Enabled by default) |
|
| Scan processes started from network drives | Scans processes that are started from mapped network drives.
(Disabled by default)
|
|
| ML Protect Scanning | Enable client-based scanning | Enables client-based
ML Protect scanning, which uses machine learning on the client system to determine whether the file matches known malware.
(Enabled by default) If the client system is connected to the Internet, ML Protect sends telemetry information to the cloud, but doesn't get automated analysis data from the cloud. Client-based scanning requires Adaptive Threat Protection or TIE server connectivity unless offline scanning is enabled.
The ML Protect technology is not supported on some Windows operating systems. See KB82761 for information. |
| Enable offline scanning | Enables client-based
ML Protect scanning to run offline, without requiring connectivity to
Trellix GTI
or the
TIE server.
(Disabled by default)
|
|
| Sensitivity level | Configures the sensitivity level to use with client-based scanning when determining whether the file matches known malware.
The higher the sensitivity level, the more malware matches. But, allowing more detections might result in more false positives. |
|
| Enable cloud-based scanning | Enables cloud-based
ML Protect scanning, which collects the attributes of the file and its behavioral information. Then, it sends this information to the machine-learning system in the cloud for analysis.
(Enabled by default) Cloud-based scanning requires connectivity to https://arc-ai1.trellix.com/.
The ML Protect technology is not supported on some Windows operating systems. See KB82761 for information. |
|
| Enable enhanced script scanning | Enables integration with AMSI (Antimalware Scan Interface).
Select this option to enhance scanning for threats in non-browser-based scripts, such as PowerShell, JavaScript, and VBScript. (Enabled by default) AMSI is a generic interface standard provided by Microsoft and supported on Windows 10, Windows Server 2016, and Windows 2019 systems. It allows applications and services to integrate with Adaptive Threat Protection, providing better protection against malware. |
|
| Enable Observe mode | Generates
ML Protect enhanced scanning events (Would Block and
Would Clean) and sends them to the server, but doesn't enforce actions.
(Enabled by default) AMSI excludes most files that are excluded from on-access scans. Some scripts, such as PowerShell, are fileless and are not excluded from AMSI. Enable enhanced scanning Observe mode temporarily on a few systems only while tuning ML Protect to evaluate the impact of ML Protect enhanced scanning.
|
|
| Enable Credential Theft Protection Scanning | Enables Credential Theft Protection scanning on client systems.
(Enabled by default) |
|
| Enable Credential Theft Protection Observe mode | Enables Credential Theft Protection Observe Mode on client systems. When this feature is enabled,
Adaptive Threat Protection events are generated and sent to
Trellix ePO - On-prem automatically.
(Disabled by default) |
|
| Rule Assignment | Specifies the set of rules that
Adaptive Threat Protection uses to calculate a reputation.
Control rules and view reputations in Server Settings → Adaptive Threat Protection.
|
|
| Productivity | Assigns the
Productivity rule group.
Use this group for high-change systems with frequent installations and updates of trusted software. This group uses the least number of rules. Users experience minimum prompts and blocks when new processes are detected. |
|
| Balanced | Assigns the
Balanced rule group.
Use this group for typical business systems with infrequent new software and changes. This group uses more rules — and users experience more prompts and blocks — than the Productivity group. |
|
| Security | Assigns the
Security rule group.
Use this group for low-change systems, such as IT-managed systems and servers with tight control. Users experience more prompts and blocks than with the Balanced group. |
|
| Action Enforcement | Trigger Dynamic Application Containment when reputation threshold reaches | Contains applications when the reputation reaches the specified threshold:
The Dynamic Application Containment reputation threshold must be above the block and clean thresholds. For example, if the block threshold is set to Known Malicious, the Dynamic Application Containment threshold must be set to Most Likely Malicious or above. When an application with the specified reputation threshold tries to run in your environment, Dynamic Application Containment allows it to run in a container and blocks or logs unsafe actions, based on containment rules. If configured, Dynamic Application Containment updates the Event Log in the Endpoint Security Client to notify you when:
|
| Block when reputation threshold reaches | Blocks files when the file reputation reaches a specific threshold, and specifies the threshold:
When a file with the specified reputation threshold tries to run in your environment, it's prevented from running but remains in place. If a file is safe and you want it to run, change its reputation to a level that allows it to run, like Might be Trusted. |
|
| Clean when reputation threshold reaches | Cleans files when the file reputation reaches a specific threshold, and specifies the threshold:
The default for the Productivity rule group is deselected.
This option must be selected to enable enhanced remediation. |
|
| Enable enhanced remediation | Monitors the behavior of processes with a reputation of
Unknown (50) and below, and their children, backs up, and remediates these changes that the processes make to the system:
(Enabled by default) Enhanced remediation is available only when the Clean when reputation threshold reaches option is enabled. |
|
| Monitor and remediate deleted and changed files | Backs up and remediates
all files, including files that the process changes or deletes.
Because backing up all file changes might consume significant disk space and negatively impact performance, by default, enhanced remediation backs up only files that the process creates. Enable this option to also back up changed and deleted files.
(Disabled by default) |
| Section | Option | Description |
|---|---|---|
| Threat Detection User Messaging | Display threat notifications to the user | Displays threat notifications to the user.
Adaptive Threat Protection depends on the Trellix system tray icon to display prompts. On systems accessed only by RDP, the system tray icon doesn't start and prompts don't appear. To work around this issue, add the UpdaterUI.exe to the logon script. See KB83532. |
| Notify the user when reputation threshold reaches | Notifies the user when the file reputation reaches a specified threshold:
The prompt level can't conflict with the clean or block settings. For example, if you block unknown files, you can't set this field to Might Be Trusted because it is above Unknown. If the notify threshold is at or above the containment threshold, when the user selects Allow, the application runs uncontained. |
|
| Default action | Specifies the action to take if the user doesn't respond to the prompt:
|
|
| Specify length (minutes) of timeout | Specifies the number of minutes to display the prompt before performing the default action.
The default is 5 minutes. |
|
| Message | Specifies the message that the user sees when a file, which meets the prompting criteria, tries to run. | |
| Disable threat notifications if the Threat Intelligence Exchange server is not reachable | Disables prompts when the TIE server is unreachable so that users don't receive prompts about files whose reputations are unavailable. | |
| Reputation Source | Use Trellix GTI if the TIE server is not reachable | Gets file reputation information from the
Global Threat Intelligence proxy if the
TIE server is unavailable.
(Enabled by default for Trellix ePO - On-prem) |
| Use only the TIE server | Gets file reputation information from the TIE server. | |
| Use only Trellix GTI | Gets file reputation information from
Trellix GTI
.
(Enabled by default for Trellix ePO - SaaS) |
|
| Sandboxing |
|
|
| Send files not yet verified for analysis | Sends executable files to
TIE server, which then sends files to Sandbox server for analysis.
When enabled, Adaptive Threat Protection sends files securely over HTTPS using port 443 when:
Specify information for the Sandbox server in the TIE settings. |
|
| Submit files when reputation threshold reaches | Submits files to
TIE server, which then sends files to Sandbox server when the file reputation reaches a specified threshold:
The default for all rule groups is Unknown. |
|
| Limit size (MB) to | Limits the size of the files sent to Sandbox server to between 1 MB and 10 MB.
The default is 5 MB. |
|
| Story Graph | Enable Story Graph Tracing |
The Story Graph in the Threat Event Log provides a visual representation of file-based and fileless-based ATP threat detection. You can examine the context of threats by reviewing the details of events leading up to a detection. |