The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure Exploit Prevention settings to block threats

Prev Next

To prevent applications from executing arbitrary code on the client system, you can configure the Exploit Prevention exclusions, default signatures, and application protection rules.

You can set the action for Trellix-defined signatures. You can enable, disable, delete, and change the inclusion status of Trellix-defined application protection rules. You can also create and duplicate your own application protection rules. Any changes you make to these rules persist through content updates.

Enable and configure Exploit Prevention to prevent buffer overflow, illegal API use, and network exploits. Create Expert Rules to prevent buffer overflow and illegal API use exploits and to protect files, registry keys, registry values, processes, and services. For the list of processes protected by Exploit Prevention, see KB58007.

Note

Host Intrusion Prevention 8.0 can be installed on the same system as Endpoint Security version 10.7. If the Host IPS or Network IPS options in McAfee Host IPS are enabled, Exploit Prevention and Network Intrusion Prevention are disabled even if enabled in the Threat Prevention settings.

Task
  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.

  2. From the Category list in the right pane, select Exploit Prevention.

  3. Click the Edit link for an editable policy.

  4. Click Show Advanced.

  5. Configure the required settings in the Exploit Prevention page, then click Save.

Option definitions

Section

Option

Definition

EXPLOIT PREVENTION Exploit Prevention

Enable Exploit Prevention

Enables the Exploit Prevention feature.

Caution

Failure to enable this option leaves your system unprotected from malware attacks.



Advanced options

Section

Option

Definition

Generic Privilege Escalation Prevention (GPEP)

Enable Generic Privilege Escalation Prevention

Enables Generic Privilege Escalation Prevention (GPEP) support. (Disabled by default)

GPEP uses Signature ID 6052 in the Exploit Prevention Content to provide coverage for privilege escalation exploits in kernel mode and user mode.

If this option is selected, Signature ID 6052 is automatically set to both Block and Report, but the Signatures section doesn't change to reflect the state.

Because GPEP might generate false positive reports, this option is disabled by default.

Windows Data Execution Prevention (DEP)

Enable Windows Data Execution Prevention

Enables Windows Data Execution Prevention (DEP) integration. (Disabled by default)

Select this option to:

  • Enable DEP for 32-bit applications in the Trellix application protection list, if not already enabled, and use it instead of Generic Buffer Overflow Protection (GBOP).Caller validation and Targeted API Monitoring are still enforced.

  • Monitor for DEP detections in the DEP-enabled 32-bit applications.

  • Monitor for DEP detections in 64-bit applications in the Trellix application protection list.

  • Log any DEP detections.

  • Log any DEP detections and send an event to Trellix ePO - On-prem.

If this option is selected, Signature ID 9990 is automatically set to both Block and Report, but the Signatures section doesn't change to reflect the state.

Disabling this option doesn't affect any processes that have DEP enabled as a result of the Windows DEP policy.

Because DEP might generate false positive reports, this option is disabled by default.

Exclusions with Caller Module or API don't apply to DEP.

Network Intrusion Prevention

Enable Network Intrusion Prevention

Enables Network Intrusion Prevention (Network IPS) and enforces network IPS signatures.

Selecting this option enables the Network IPS filter and exposes Network IPS signatures in the Signatures list.

Automatically block network Intruders

Blocks intruder hosts for a specified number of seconds. Select this option to block all attempted actions from intruder hosts, even if the action for the Network IPS signature isn't set to Block.

  • Number of seconds (1-9999) to block — Specifies the number of seconds to automatically block intruders.

Blocked Hosts

Lists systems that Network IPS is blocking communication from. When Automatically block network intruders is selected, Network IPS automatically blocks systems when it detects an attack.

  • Delete — Deletes the selected system from the Blocked Hosts table. When you click Apply, the system is unblocked.

  • Host — Lists the IP address of the blocked system.

  • Time Remaining (seconds) — Indicates the number of seconds until Network IPS no longer blocks the system.

  • Status — Indicates whether the system is blocked or unblocked.

Exclusions

Specifies the process, caller module, API, signatures, or services to exclude.

Exclusions with Caller Module or API don't apply to DEP.

Add

Creates an exclusion and adds it to the list.

Delete

Deletes the selected item.

Double-click an item

Changes the selected item.

Duplicate

Creates a copy of the selected item.

Actions

  • Edit — Changes the selected item.

  • Duplicate — Creates a copy of the selected item.

Sort options

Sort the Exclusions list by:

  • Type

  • Process Name

  • Caller Module Name

  • API Name

  • Signature IDs

  • Service Name

  • IP Addresses

  • Actions

Signatures

Changes the action for Exploit Prevention signatures. To disable a signature, deselect Block and Report.

By default, only high-severity signatures are set to Block.

The Notes column in the Signatures list refers to KB51504 for details about supported platforms. To view this article, you must first log on to the ServicePortal, then search the Knowledge Center for KB51504.

You can't select Block or Report for Signature IDs 6052 and 9990.

To enable Signature ID 6052, select Enable Generic Privilege Escalation Prevention. To enable Signature ID 9990, select Enable Windows Data Execution Prevention. The Signatures section doesn't change to reflect the state.

Filter options

Filters the Signatures list by:

Type

Processes

  • Buffer Overflow

  • Illegal API Use

  • Files

  • Services

  • Registry

  • Processes

  • Network IPS

The Network IPS filter is only available when Enable Network Intrusion Prevention is selected.

Severity

  • High

  • Medium

  • Low

  • Others (signatures with a severity of Informational or Disabled)

Status

  • Enabled

  • Disabled

Origin

  • Trellix-defined

  • User-defined

Quick find

Filters the list by specifying a term to search for.

  • Apply — Starts the search.

  • Clear — Deletes text from the Quick find field.

Show selected rows

Filters out unselected rows, showing only selected rows.

Show Filter/ Hide Filter

Displays or hides the filter options.

Block (only)

Blocks behavior that matches the signature without logging.

Report (only)

Logs behavior that matches the signature without blocking.

Block and Report

Blocks and logs behavior that matches the signature.

Block All

Selects or deselects Block for all signatures.

Report All

Selects or deselects Report for all signatures.

Add Expert Rule

Creates an Expert Rule to:

  • Protect files, registry keys and values, processes, or services.

  • Prevent buffer overflow or illegal API use exploits.

You can't create Network IPS Expert Rules.

To check for syntax errors, select a user-defined Expert Rule and click Add Expert Rule. Expert Rule Checker opens so you can change, check, and enforce the Expert Rule.

Delete

Deletes the selected item.

Double-click an item

Changes the selected item. (User-defined rules only)

ActionsExport Table

Exports all signatures in the list to a defined format.

Actions

  • Edit — Changes the selected item. (User-defined rules only)

  • View — Displays the signature description for the selected item. (Trellix-defined rules only)

Application Protection Rules

Specifies the applications that Exploit Prevention monitors. Exploit Prevention only monitors the processes in the Application Protection list with the inclusion status of Include.

Add

Creates an Application Protection rule and adds it to the list.

Delete

Deletes the selected item. (User-defined rules only)

Double-click an item

Changes the selected item. (User-defined rules only)

Duplicate

Creates a copy of the selected item. (User-defined rules only)

Actions

  • Edit — Changes the selected item.

  • Duplicate — Creates a copy of the selected item. (User-defined rules only)



Important

Registry READ operations are very expensive in terms of system resources and performance. These rules should only be used in emergency situations due to the expected performance issues that can occur and are not intended for general use.