Configure a policy to search for data of loaded DLLs

Prev Next

To search for data of loaded DLLs on single or multiple endpoints, you must enable the Windows image load events option in EDRF policy.

DLL is a commonly used attack vector for malware and also to exploit vulnerable software. The malicious DLL files include malware instructions and might even show as legitimate DLL by having the same name with different path to hide its presence. By configuring the policy to send DLL data, you can see the details of its presence and how it executed in your environment.

  1. Log on to ePO - On-prem or ePO - SaaS.

  2. Select MenuPolicyPolicy Catalog.

  3. From the Product drop-down list, select Trellix EDR.

  4. Select My Default.

  5. On the Trace tab, select Include All ImageLoad Events and click Save.

    After you create a policy, assign it to managed endpoints to configure the EDRF clients on those endpoints.

    For details about assigning a policy to managed endpoints, see ePO - On-prem or ePO - SaaS Product Guide.

The endpoint starts sending DLLs image load events only for CLI (Command-Line Interface) processes to the EDRF. You can now search for loaded DLLs on Device Search and Historical Search.