To prevent applications from executing arbitrary code on the client system, you can configure the Exploit Prevention exclusions, default signatures, and application protection rules.
Note
Exploit Prevention is not supported in the ARM architecture.
Before you begin
Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.
You can set the action for Trellix -defined signatures. You can enable, disable, delete, and change the inclusion status of Trellix-defined application protection rules. You can also create and duplicate your own application protection rules. Any changes you make to these rules persist through content updates.
For the list of processes protected by Exploit Prevention, see KB58007.
Task
Open the Trellix Endpoint Security (ENS) Client.
Click Threat Prevention on the main Status page.
Or, from the Action menu
, select Settings, then click Threat Prevention on the Settings page.Click Show Advanced.
Click Exploit Prevention.
Configure settings on the page, then click Apply.