To prevent applications from executing arbitrary code on the client system, you can configure the Exploit Prevention exclusions, default signatures, and application protection rules.
You can set the action for Trellix-defined signatures. You can enable, disable, delete, and change the inclusion status of Trellix-defined application protection rules. You can also create and duplicate your own application protection rules. Any changes you make to these rules persist through content updates.
Enable and configure Exploit Prevention to prevent buffer overflow, illegal API use, and network exploits. Create Expert Rules to prevent buffer overflow and illegal API use exploits and to protect files, registry keys, registry values, processes, and services. For the list of processes protected by Exploit Prevention, see KB58007.
Note
Host Intrusion Prevention 8.0 can be installed on the same system as Endpoint Security version 10.7. If the Host IPS or Network IPS options in McAfee Host IPS are enabled, Exploit Prevention and Network Intrusion Prevention are disabled even if enabled in the Threat Prevention settings.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.
From the Category list in the right pane, select Exploit Prevention.
Click the Edit link for an editable policy.
Click Show Advanced.
Configure the required settings in the Exploit Prevention page, then click Save.
Section | Option | Definition |
|---|---|---|
Exploit Prevention | Enable Exploit Prevention | Enables the Exploit Prevention feature.
|
Section | Option | Definition | |
|---|---|---|---|
Generic Privilege Escalation Prevention (GPEP) | Enable Generic Privilege Escalation Prevention | Enables Generic Privilege Escalation Prevention (GPEP) support. (Disabled by default) GPEP uses Signature ID 6052 in the Exploit Prevention Content to provide coverage for privilege escalation exploits in kernel mode and user mode. If this option is selected, Signature ID 6052 is automatically set to both Block and Report, but the Signatures section doesn't change to reflect the state. Because GPEP might generate false positive reports, this option is disabled by default. | |
Windows Data Execution Prevention (DEP) | Enable Windows Data Execution Prevention | Enables Windows Data Execution Prevention (DEP) integration. (Disabled by default) Select this option to:
If this option is selected, Signature ID 9990 is automatically set to both Block and Report, but the Signatures section doesn't change to reflect the state. Disabling this option doesn't affect any processes that have DEP enabled as a result of the Windows DEP policy. Because DEP might generate false positive reports, this option is disabled by default. Exclusions with Caller Module or API don't apply to DEP. | |
Network Intrusion Prevention | Enable Network Intrusion Prevention | Enables Network Intrusion Prevention (Network IPS) and enforces network IPS signatures. Selecting this option enables the Network IPS filter and exposes Network IPS signatures in the Signatures list. | |
Automatically block network intruders | Blocks intruder hosts for a specified number of seconds. Select this option to block all attempted actions from intruder hosts, even if the action for the Network IPS signature isn't set to Block.
| ||
Exclusions | Specifies the process, caller module, API, signatures, or services to exclude. Exclusions with Caller Module or API don't apply to DEP. | ||
Add | Creates an exclusion and adds it to the list. | ||
Delete | Deletes the selected item. | ||
Actions |
| ||
Sort options | Sort the Exclusions list by:
| ||
Signatures | Changes the action for Exploit Prevention signatures. To disable a signature, deselect Block and Report. By default, only high-severity signatures are set to Block. The Notes column in the Signatures list refers to KB51504 for details about supported platforms. To view this article, you must first log on to the ServicePortal, then search the Knowledge Center for KB51504. You can't select Block or Report for Signature IDs 6052 and 9990. To enable Signature ID 6052, select Enable Generic Privilege Escalation Prevention. To enable Signature ID 9990, select Enable Windows Data Execution Prevention. The Signatures section doesn't change to reflect the state. | ||
Filter options | Filters the Signatures list by: | ||
Type |
| ||
Severity |
| ||
Status |
| ||
Origin |
| ||
Quick find | Filters the list by specifying a term to search for.
| ||
Show selected rows | Filters out unselected rows, showing only selected rows. | ||
Show Filter/ Hide Filter | Displays or hides the filter options. | ||
Block (only) | Blocks behavior that matches the signature without logging. | ||
Report (only) | Logs behavior that matches the signature without blocking. | ||
Block and Report | Blocks and logs behavior that matches the signature. | ||
Block All | Selects or deselects Block for all signatures. | ||
Report All | Selects or deselects Report for all signatures. | ||
Add Expert Rule | Creates an Expert Rule to:
You can't create Network IPS Expert Rules. | ||
Delete | Deletes the selected item. | ||
Actions → Export Table | Exports all signatures in the list to a defined format. | ||
Actions |
| ||
Application Protection Rules | Specifies the applications that Exploit Prevention monitors. Exploit Prevention only monitors the processes in the Application Protection list with the inclusion status of Include. | ||
Add | Creates an Application Protection rule and adds it to the list. | ||
Delete | Deletes the selected item. (User-defined rules only) | ||
Actions |
| ||