Configure EDRF policies

Prev Next

The EDRF Policy Catalog is where you to define and manage how the agent functions on your endpoints. Each policy contains settings that control security features, performance, and data collection. By configuring these policies, you ensure that your security rules are enforced consistently across all managed systems.

What you can achieve

  • Protect the EDRF Client from tampering and unauthorized removal.

  • Manage CPU usage and event storage to balance security with endpoint performance.

  • Configure malware scanning, quarantine actions, and policy exclusions.

  • Control the flow of trace data from endpoints to the cloud for threat analysis.

  • Define real-time monitoring for suspicious activities and indicators of compromise (IOCs).

  • Isolate compromised endpoints to prevent threats from spreading.

Note

The policies listed in this catalog are the default configurations. We strongly recommend that you review these settings and customize them to align with your organization's specific security and performance requirements before deployment.

How to edit a policy

All policies are configured from the Trellix ePO console.

  1. From the ePO console, navigate to MenuPolicyPolicy Catalog.

  2. From the Product drop-down menu, select Trellix EDR with Forensics.

  3. Find the policy you want to modify and click Edit.

Note

To see all available options in the General policy, click Show Advanced.

Create a custom policy

While you can edit the default policies directly, we recommend that you create custom policies. This approach allows you to assign different configurations to specific endpoint groups (for example, servers and workstations).

To create a custom policy:

  1. Navigate to the Policy Catalog and select Trellix EDR with Forensics.

  2. Select the policy you want to use as a template (for example, the default Trellix EDR with Forensics Detection policy).

  3. Click the Duplicate action button.

  4. Provide a descriptive name for the new policy and save it.

  5. Edit your new, duplicated policy as required. Once configured, assign this custom policy to the appropriate endpoint groups in your System Tree.