Configuring a tamper protection policy

Prev Next

The Endpoint Security Agent (HX) Tamper Protection policy allows you to protect the Endpoint Security Agent (HX) software on your Windows endpoints so that you can have full control over the programs and applications running on your endpoints. This Endpoint Security Agent (HX) policy has three protection components. It prevents Endpoint Security Agent (HX) services from being stopped and restarted on your endpoints, protects the Endpoint Security Agent (HX) process from injection and inspection, and prevents unauthorized users from tampering with files and folders.

Note

Trellix Endpoint Security Agent (HX) version 20 or later supports the Tamper Protection policy's injection and inspection protection component for Windows endpoints only.

Trellix Endpoint Security Agent (HX) version 29 or later supports the Tamper Protection policy's start and stop functionality for Endpoint Security Agent (HX) services on Windows endpoints only.

Trellix Endpoint Security Agent (HX) version 33 or later supports the Tamper Protection policy's prevention of unauthorized users tampering with files and folders on Windows endpoints only.

Trellix Endpoint Security Agent (HX) version 35.31.22 or later supports the Tamper Protection policy's prevention of SYSTEM users tampering with files and folders on Windows endpoints only.

Trellix does not recommend disabling your Tamper Protection policy because it may allow users with administrative rights, threat actors, and malware to compromise your endpoint protection.

By default, the tamper protection policy is turned on (enabled) for all Windows endpoints. This means your system administrator cannot stop or restart the Endpoint Security Agent (HX) service, inspect or inject code into the agent process, or allow unauthorized user tampering with Endpoint Security Agent (HX) files and folders. Though not recommended, you can disable the Tamper Protection policy. When the policy is disabled, your system administrators can start and stop Endpoint Security Agent (HX) services, inspect Endpoint Security Agent (HX) processes, perform injection activities on your Windows endpoints, and manipulate Endpoint Security Agent (HX) files and folders. This gives administrators greater control over programs running on the endpoint during troubleshooting and investigations.

Use the Endpoint Security (HX) Server Web UI or API to modify your agent default policy and disable the tamper protection policy for all host endpoints in your enterprise, or to create a custom policy to enable or disable the tamper protection policy for selected host sets in your environment.

The Tamper Protection settings are dynamic, which means they do not cause the Endpoint Security Agent (HX) to restart on your endpoints.

This section covers how to use the Web UI to enable or disable the tamper protection policy. See the Endpoint Security (HX) API pages for information on using the API to manage your tamper protection policies.