You can create Expert rules to protect the Windows Services (Windows versions 8.0 and earlier only). You can also create custom Services rules in the Access Protection policy in Threat Prevention. But, these rules don't provide the complete functionality available with Expert rules.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.
From the Category list in the right pane, select Exploit Prevention.
Click the Edit link for an editable policy.
Click Show Advanced.
In the Signatures section, click Add Expert Rule.
In the Expert Rules Properties page, complete the fields.
Trellix ENS assigns the ID number for the rule automatically starting with 20000.
In the Rule Name, provide a unique name for the Expert rule.
Select Block and Report actions for the rule by selecting the corresponding checkboxes.
Trellix recommends selecting Report action for initial validation. You can select Block and Report check boxes after validating that the rule works appropriately.
Select the Severity level according to the Expert rule.
The severity provides information only; it has no effect on the rule action.
Select the Use Expert Rule template checkbox. This populates a template rule in the Rule content box based on the Rule type you select.
To get a blank template for writing the Expert rules, deselect Use Expert Rule template.
Select Services in the Rule type drop-down list.
Save the rule, then save the settings.
Validate the new policy on a client system.
Enforce the policy on the client systems.