Argument details

Prev Next

This table lists the commands with the supported arguments and their description. In the Argument column, the supported arguments for the commands are listed in alphabetical order.

Argument details

Command

Argument

Description

attr

-a

Always authorizes by file name. This is a deprecated technique. For more information, contact Trellix Support.

-p

Bypasses from process context file operations attribute.

-u

Always unauthorizes by file name. This is a deprecated technique. For more information, contact Trellix Support.

auth

-a

Authorizes a binary using the checksum value.

-b

Bans a binary using the checksum value.

-t

Includes a rule-id associated to the updater-related actions.

-u

Authorizes a binary and also provides updater rights when used with the -a argument.

begin-update (bu)

workflow-id

Indicates to specify an ID while switching to the Update mode. This ID can be used for tracking purposes in a change management for ticketing system.

comment

Indicates to use a descriptive text for the workflow ID.

check

-r

Fixes any inconsistencies that are encountered.

config

-a

Appends the configuration values.

disable

NA

NA

enable

NA

NA

end-update (eu)

NA

NA

event

-a

Adds sinks to the specified event.

-r

Removes sinks from the specified event.

features

-d

Lists all features (including the hidden features).

For more information, contact Trellix Support.

help

NA

NA

help-advanced

NA

NA

license

NA

NA

list-solidified (ls)

-l

Lists details of files in the allow list.

list-unsolidified (lu)

NA

NA

lockdown

NA

NA

monitor (mon)

-a

Includes the specified pattern to match file names for content change tracking. The pattern can contain the '*' character, as the first or last character. For example, *.txt and hello.*.

This argument is useful on ePO - On-prem-managed configuration. The content change tracking for files can be viewed only at ePO - On-prem.

-b

Excludes the specified pattern to match file names for content change tracking. The pattern can contain the '*' character, as the first or last character. For example, *.txt and hello.*.

This argument is useful on ePO - On-prem-managed configuration. The content change tracking for files can be viewed only at ePO - On-prem.

-c

Includes the directory non-recursively for content change tracking. This argument is useful on ePO - On-prem-managed configuration. The content change tracking for files can be viewed only at ePO - On-prem.

-d

Includes the file for content change tracking. This argument can be specified with the -i argument or alone. The -d argument is useful on ePO - On-prem-managed configuration. The content change tracking for files can be viewed only at ePO - On-prem.

-e

Excludes the specified component for monitoring changes.

-f

Flushes all monitoring or content change tracking rules.

-i

Includes the specified component for monitoring changes.

-n

(Optional) Specifies the file encoding. The supported encoding types are Auto-Detect, UTF-8, UTF-16, and ASCII, If the -n option is not used, the encoding used is Auto-Detect. The -n argument can only be specified with -d argument.

-r

Removes all monitoring rules.

passwd

-d

Removes the password for using Application Control.

read-protect (rp)

-e

Excludes specific components from a read-protected directory, or volume.

-f

Flushes all components from read protection.

-i

Includes files, directories, or volumes for read protection.

-l

Lists the read-protected components.

-r

Removes read protection applied to files, directories, or volumes.

recover

-f

Forcefully closes the ePO - On-prem command and recover the local CLI.

skiplist

-s

Removes files present under the specified path component and subdirectories from the allow list.

solidify (so)

-q

Suppresses all output except for errors.

-v

Displays all processed components.

status

NA

NA

trusted

-e

Excludes one or more specified paths to the directories or volumes from a list of trusted directories or volumes.

-f

Removes all directories and volumes from the trusted rule.

-i

Adds one or more specified paths to the directories or volumes as trusted directories or volumes.

-l

Lists all trusted directories and volumes.

-r

Removes the specified directories or volumes from the trusted rule.

unsolidify (unso)

-v

Displays all processed components.

updaters

-d

Excludes the child processes of a binary file to be added as an updater from inheriting the updater rights.

-n

Disables event logging for a file to be added as an updater.

-p

Adds a file as an updater only when it is started by specified parent process.

-t

Performs these operations:

  • Includes the tags for a file to be added as an updater.

  • Adds a user with a tag name as an updater.

version

NA

NA

write-protect (wp)

-e

Excludes specific components from a write-protected directory or volume.

-f

Flushes all components from write protection.

-i

Write-protects files, directories, or volumes.

-l

Lists the write-protected components.

-r

Removes write protection applied to files, directories, or volumes.