You can define rules to ban an application or executable file from running on all endpoints in the enterprise based on the SHA-1 or SHA-256 value of the file.
On the ePO - SaaS console, select Menu → Application Control → Policy Discovery to open the Policy Discovery page.
Select the requests where you want to define rules.
Click Actions → Ban File Globally.
The Ban File Globally dialog box provides details and prompts you to confirm the action.
Click OK.
Rules are created for the files associated with the selected requests and added to the Global Rules rule group included in the Trellix Default policy.
Ban the files that have already been added to the endpoint.
Click the application name link.
The Files page lists all executable files installed on the endpoint.
Select all listed files.
Click Actions → Ban Files to open the Allow or Ban Files wizard.
Specify the rule group for the rules.
To add the rules to an existing rule group, select Add to Existing Rule Group, select the rule group from the list, and specify the operating system.
To create a rule group with the rules, select Create a New Rule Group, enter the rule group name, and specify the operating system.
Make sure that the rule group where you add the rules is added to a policy that is applied on the endpoint where the request was received.
Click Next.
Review the rules, then click Save.