Change the behavior of Trellix-defined rules or create custom rules to protect your managed access points.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Product list.
From the Category list, select Access Protection.
Click the name of an editable policy.
Click the name of an editable policy.
- <cmd>From the<uicontrol>Action</uicontrol>menu<image></image>, select<uicontrol>About</uicontrol>.</cmd>
Select the platform as Linux.
Change a Trellix-defined rule: In the Rules section, select the rule, then click Edit.
On the Rule page, configure rule options.
In the Executables section, click Add, configure executable properties, then click Save twice to save the rule.
Create a custom rule: In the Rules section, click Add .
On the Rule page, configure the settings.
Create a custom rule: In the Rules section, click Add .
Create a custom rule: In the Rules section, click Add .
In the User Names section, click Add, configure user name properties, then click Save.
Create a custom rule: In the Rules section, click Add .
Create a custom rule: In the Rules section, click Add .
Tip
Best practice: To avoid impacting performance, don't select the Read operation.
In the Targets section, click Add, configure target information, then click Save three times.
Specify the behavior of the rule: Create a custom rule: In the Rules section, click Add .
To select or deselect all rules under Block or Report, click Block All or Report All.
Create a custom rule: In the Rules section, click Add .
Click Save.