This table lists the commands with the supported arguments and their description. In the Argument column, the supported arguments for the commands are listed in alphabetical order.
| Command | Argument | Description |
|---|---|---|
| attr | -a | Always authorizes by file name. This is a deprecated technique. For more information, contact Trellix Support. |
| -p | Bypasses from process context file operations attribute. | |
| -u | Always unauthorizes by file name. This is a deprecated technique. For more information, contact Trellix Support. | |
| auth | -a | Authorizes a binary using the checksum value. |
| -b | Bans a binary using the checksum value. | |
| -t | Includes a rule-id associated to the updater-related actions. | |
| -u | Authorizes a binary and also provides updater rights when used with the -a argument. | |
| begin-update (bu) | workflow-id | Indicates to specify an ID while switching to the Update mode. This ID can be used for tracking purposes in a change management for ticketing system. |
| comment | Indicates to use a descriptive text for the workflow ID. | |
| check | -r | Fixes any inconsistencies that are encountered. |
|
config |
-a | Appends the configuration values. |
| disable | NA | NA |
| enable | NA | NA |
| end-update (eu) | NA | NA |
| event | -a | Adds sinks to the specified event. |
| -r | Removes sinks from the specified event. | |
| features | -d | Lists all features (including the hidden features).
For more information, contact Trellix Support. |
| help | NA | NA |
| help-advanced | NA | NA |
| license | NA | NA |
| list-solidified (ls) | -l | Lists details of the whitelisted files. |
| list-unsolidified (lu) | NA | NA |
| lockdown | NA | NA |
| monitor (mon) | -a | Includes the specified pattern to match file names for content change tracking. The pattern can contain the
'*' character, as the first or last character. For example,
*.txt and
hello.*.
This argument is useful on Trellix ePO - On-prem-managed configuration. The content change tracking for files can be viewed only at Trellix ePO - On-prem. |
| -b | Excludes the specified pattern to match file names for content change tracking. The pattern can contain the
'*' character, as the first or last character. For example,
*.txt and
hello.*.
This argument is useful on Trellix ePO - On-prem-managed configuration. The content change tracking for files can be viewed only at Trellix ePO - On-prem. |
|
| -c | Includes the directory non-recursively for content change tracking. This argument is useful on Trellix ePO - On-prem-managed configuration. The content change tracking for files can be viewed only at Trellix ePO - On-prem. | |
| -d | Includes the file for content change tracking. This argument can be specified with the -i argument or alone. The -d argument is useful on Trellix ePO - On-prem-managed configuration. The content change tracking for files can be viewed only at Trellix ePO - On-prem. | |
| -e | Excludes the specified component for monitoring changes. | |
| -f | Flushes all monitoring or content change tracking rules. | |
| -i | Includes the specified component for monitoring changes. | |
| -n | (Optional) Specifies the file encoding. The supported encoding types are Auto-Detect, UTF-8, UTF-16, and ASCII, If the -n option is not used, the encoding used is Auto-Detect. The -n argument can only be specified with -d argument. | |
| -r | Removes all monitoring rules. | |
| passwd | -d | Removes the password for using Application Control. |
| read-protect (rp) | -e | Excludes specific components from a read-protected directory, or volume. |
| -f | Flushes all components from read protection. | |
| -i | Includes files, directories, or volumes for read protection. | |
| -l | Lists the read-protected components. | |
| -r | Removes read protection applied to files, directories, or volumes. | |
| recover | -f | Forcefully closes the Trellix ePO - On-prem command and recover the local CLI. |
| solidify (so) | -q | Suppresses all output except for errors. |
| -v | Displays all processed components. | |
| status | NA | NA |
| trusted | -e | Excludes one or more specified paths to the directories or volumes from a list of trusted directories or volumes. |
| -f | Removes all directories and volumes from the trusted rule. | |
| -i | Adds one or more specified paths to the directories or volumes as trusted directories or volumes. | |
| -l | Lists all trusted directories and volumes. | |
| -r | Removes the specified directories or volumes from the trusted rule. | |
| unsolidify (unso) | -v | Displays all processed components. |
| updaters | -d | Excludes the child processes of a binary file to be added as an updater from inheriting the updater rights. |
| -n | Disables event logging for a file to be added as an updater. | |
| -p | Adds a file as an updater only when it is started by specified parent process. | |
| -t | Performs these operations:
|
|
| version | NA | NA |
| write-protect (wp) | -e | Excludes specific components from a write-protected directory or volume. |
| -f | Flushes all components from write protection. | |
| -i | Write-protects files, directories, or volumes. | |
| -l | Lists the write-protected components. | |
| -r | Removes write protection applied to files, directories, or volumes. |