The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure Exploit Prevention settings to block threats

Prev Next

To prevent applications from executing arbitrary code on the client system, you can configure the Exploit Prevention exclusions, default signatures, and application protection rules.

You can set the action for Trellix-defined signatures. You can enable, disable, delete, and change the inclusion status of Trellix-defined application protection rules. You can also create and duplicate your own application protection rules. Any changes you make to these rules persist through content updates.

Enable and configure Exploit Prevention to prevent buffer overflow, illegal API use, and network exploits. Create Expert Rules to prevent buffer overflow and illegal API use exploits and to protect files, registry keys, registry values, processes, and services. For the list of processes protected by Exploit Prevention, see KB58007.

Note

Host Intrusion Prevention 8.0 can be installed on the same system as Endpoint Security version 10.7. If the Host IPS or Network IPS options in McAfee Host IPS are enabled, Exploit Prevention and Network Intrusion Prevention are disabled even if enabled in the Threat Prevention settings.

Task
  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.

  2. From the Category list in the right pane, select Exploit Prevention.

  3. Click the Edit link for an editable policy.

  4. Click Show Advanced.

  5. Configure the required settings in the Exploit Prevention page, then click Save.

Option definitions

Section

Option

Definition

Exploit Prevention

Enable Exploit Prevention

Enables the Exploit Prevention feature.

Caution

Failure to enable this option leaves your system unprotected from malware attacks.



Advanced options

Section

Option

Definition

Generic Privilege Escalation Prevention (GPEP)

Enable Generic Privilege Escalation Prevention

Enables Generic Privilege Escalation Prevention (GPEP) support. (Disabled by default)

GPEP uses Signature ID 6052 in the Exploit Prevention Content to provide coverage for privilege escalation exploits in kernel mode and user mode.

If this option is selected, Signature ID 6052 is automatically set to both Block and Report, but the Signatures section doesn't change to reflect the state.

Because GPEP might generate false positive reports, this option is disabled by default.

Windows Data Execution Prevention (DEP)

Enable Windows Data Execution Prevention

Enables Windows Data Execution Prevention (DEP) integration. (Disabled by default)

Select this option to:

  • Enable DEP for 32-bit applications in the Trellix application protection list, if not already enabled, and use it instead of Generic Buffer Overflow Protection (GBOP). Caller validation and Targeted API Monitoring are still enforced.

  • Monitor for DEP detections in the DEP-enabled 32-bit applications.

  • Monitor for DEP detections in 64-bit applications in the Trellix application protection list.

  • Log any DEP detections and send an event to ePO - On-prem.

If this option is selected, Signature ID 9990 is automatically set to both Block and Report, but the Signatures section doesn't change to reflect the state.

Disabling this option doesn't affect any processes that have DEP enabled as a result of the Windows DEP policy.

Because DEP might generate false positive reports, this option is disabled by default.

Exclusions with Caller Module or API don't apply to DEP.

Network Intrusion Prevention

Enable Network Intrusion Prevention

Enables Network Intrusion Prevention (Network IPS) and enforces network IPS signatures.

Selecting this option enables the Network IPS filter and exposes Network IPS signatures in the Signatures list.

Automatically block network intruders

Blocks intruder hosts for a specified number of seconds. Select this option to block all attempted actions from intruder hosts, even if the action for the Network IPS signature isn't set to Block.

  • Number of seconds (1-9999) to block — Specifies the number of seconds to automatically block intruders.

Exclusions

Specifies the process, caller module, API, signatures, or services to exclude.

Exclusions with Caller Module or API don't apply to DEP.

Add

Creates an exclusion and adds it to the list.

Delete

Deletes the selected item.

Actions

  • Edit — Changes the selected item.

  • Duplicate — Creates a copy of the selected item.

Sort options

Sort the Exclusions list by:

  • Type

  • Process Name

  • Caller Module Name

  • API Name

  • Signature IDs

  • Service Name

  • IP Addresses

  • Actions

Signatures

Changes the action for Exploit Prevention signatures. To disable a signature, deselect Block and Report.

By default, only high-severity signatures are set to Block.

The Notes column in the Signatures list refers to KB51504 for details about supported platforms. To view this article, you must first log on to the ServicePortal, then search the Knowledge Center for KB51504.

You can't select Block or Report for Signature IDs 6052 and 9990. To enable Signature ID 6052, select Enable Generic Privilege Escalation Prevention. To enable Signature ID 9990, select Enable Windows Data Execution Prevention. The Signatures section doesn't change to reflect the state.

Filter options

Filters the Signatures list by:

Type

  • Buffer Overflow

  • Illegal API Use

  • Files

  • Services

  • Registry

  • Processes

  • Network IPS

    The Network IPS filter is only available when Enable Network Intrusion Prevention is selected.

Severity

  • High

  • Medium

  • Low

  • Others (signatures with a severity of Informational or Disabled)

Status

  • Enabled

  • Disabled

Origin

  • Trellix-defined

  • User-defined

Quick find

Filters the list by specifying a term to search for.

  • Apply — Starts the search.

  • Clear — Deletes text from the Quick find field.

Show selected rows

Filters out unselected rows, showing only selected rows.

Show Filter/ Hide Filter

Displays or hides the filter options.

Block (only)

Blocks behavior that matches the signature without logging.

Report (only)

Logs behavior that matches the signature without blocking.

Block and Report

Blocks and logs behavior that matches the signature.

Block All

Selects or deselects Block for all signatures.

Report All

Selects or deselects Report for all signatures.

Add Expert Rule

Creates an Expert Rule to:

  • Protect files, registry keys and values, processes, or services.

  • Prevent buffer overflow or illegal API use exploits.

You can't create Network IPS Expert Rules.

Delete

Deletes the selected item.

ActionsExport Table

Exports all signatures in the list to a defined format.

Actions

  • Edit — Changes the selected item. (User-defined rules only)

  • View — Displays the signature description for the selected item. (Trellix-defined rules only)

Application Protection Rules

Specifies the applications that Exploit Prevention monitors. Exploit Prevention only monitors the processes in the Application Protection list with the inclusion status of Include.

Add

Creates an Application Protection rule and adds it to the list.

Delete

Deletes the selected item. (User-defined rules only)

Actions

  • Edit — Changes the selected item.

  • Duplicate — Creates a copy of the selected item. (User-defined rules only)