You can create Expert rules to prevent illegal use of the Exploit Prevention API. The Expert Rules can only extend the functionality of the Illegal API Use signatures provided by Exploit Prevention content. Expert Rules can't refer to APIs that aren't already covered in an Illegal API Use signature available in content.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.
From the Category list in the right pane, select Exploit Prevention.
Click the Edit link for an editable policy.
Click Show Advanced.
In the Signatures section, click Add Expert Rule.
In the Expert Rules Properties page, complete the fields.
ENS assigns the ID number for the rule automatically starting with 20000.
In the Rule Name, provide a unique name for the Expert rule.
Select Block and Report actions for the rule by selecting the corresponding checkboxes.
Trellix recommends selecting Report action for initial validation. You can select Block and Report check boxes after validating that the rule works appropriately.
Select the Severity level according to the Expert rule.
The severity provides information only; it has no effect on the rule action.
Select the Use Expert Rule template checkbox. This populates a template rule in the Rule content box based on the Rule type you select.
To get a blank template for writing the Expert rules, deselect Use Expert Rule template.
Select Illegal API Use in the Rule type drop-down list.
Save the rule, then save the settings.
Validate the new policy on a client system.
Enforce the policy on the client systems.