The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Adaptive Threat Protection policy

Prev Next

Adaptive Threat Protection is an optional Trellix ENS module that analyzes content from your enterprise and decides what to do based on file reputation, rules, and reputation thresholds.

Note

Adaptive Threat Protection is supported on systems managed by Trellix ePO - On-prem and systems managed by Trellix ePolicy Orchestrator - SaaS. Adaptive Threat Protection is not supported on standalone systems.

Adaptive Threat Protection includes the ability to block, or clean files, based on reputation.

Adaptive Threat Protection is an optional Trellix ENS module. For additional threat intelligence sources and functionality, deploy the Threat Intelligence Exchange server. For information, contact your reseller or sales representative.

Note

For installing Adaptive Threat Protection, you must have installed Trellix ENS Threat Prevention.

If TIE server and Trellix DXL are not present, Adaptive Threat Protection communicates with Trellix GTI for file reputation information.

You can run Adaptive Threat Protection in async and sync modes. By default, when you deploy Adaptive Threat Protection from ePO - On-prem without any arguments (such as sync), Adaptive Threat Protectionis installed in async mode. You can switch to sync mode by using the command-line option. For more information about using the command, see Trellix Endpoint Security (ENS) for Mac installation guide.

Threat Prevention and Adaptive Threat Protection can run in both sync and async modes. There is no inter-dependency that both the modules have to run in the same mode.