The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure Exploit Prevention settings to block threats on a client system

Prev Next

To prevent applications from executing arbitrary code on the client system, you can configure the Exploit Prevention exclusions, default signatures, and application protection rules.

Note

Exploit Prevention is not supported in the ARM architecture.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.

You can set the action for Trellix -defined signatures. You can enable, disable, delete, and change the inclusion status of Trellix-defined application protection rules. You can also create and duplicate your own application protection rules. Any changes you make to these rules persist through content updates.

For the list of processes protected by Exploit Prevention, see KB58007.

Task

  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Threat Prevention on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Threat Prevention on the Settings page.

  3. Click Show Advanced.

  4. Click Exploit Prevention.

  5. Configure settings on the page, then click Apply.