Use this file to discover all available pages before exploring further.
The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.
You can configure an executable associated with a rule or group.
Firewall treats all files and folder names in rules as case insensitive.For example, if a
Firewall rule specifies to block C:\Temp\FTP.exe,
Firewall also blocks C:\temp\ftp.exe and c:\TEMP\FTP.EXE.
Options
Option
Definition
Name
Specifies the name that you call the executable.
This field is required with at least one other field:
File name or path,
File description,
MD5 hash, or signer.
File name or path
Specifies the file name or path of the executable to add or edit.
Click
Browse to select the executable.
The file name or path can include wildcards.
File description
Indicates the description of the file. This field is used to verify an application's file description inside the executable itself.
To view the file description for an executable, right-click the executable, select
Properties, then click the
Details tab to see the
Description information.
Note
File description is not a comment field. To add comments to an executable, use the
Notes field.
MD5 hash
Indicates the MD5 hash (32-digit hexadecimal number) of the process.
Signer
Enable digital signature check —
Guarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash.
If enabled, specify:
Allow any signature — Allows files signed by any process signer.
Signed by — Allows only files signed by the specified process signer.
A signer distinguished name (SDN) for the executable is required and it must match exactly the entries in the accompanying field, including commas and spaces.
The process signer appears in the correct format in the events in the log files. For example:
C=US, ST=WASHINGTON, L=REDMOND, O=MICROSOFT CORPORATION, OU=MOPR, CN=MICROSOFT WINDOWS
Note
You can enter
S
for the state or ProvinceName object identifier, but the element automatically appears as