Disabling Tamper Protection for selected host sets

Prev Next

To allow your system administrators to stop and restart Trellix Endpoint Security (HX) xAgent services for selected host sets in your environment, use the Web UI to create or modify a custom policy that disables the Tamper Protection policy. The tamper protection policy will apply to Windows hosts running Endpoint Security (HX) xAgent version 29 or later only for the selected host sets.

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

Important

: Trellix does not recommend disabling your Tamper Protection policy because it may allow users with administrative rights, threat actors, and malware to compromise your endpoint protection.

To allow the stop and restart of agent services on selected host sets:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click link for the custom policy you want to modify.

  4. Click the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Deny local admin permission to Start and Stop to OFF.

  6. Click Save to save the policy settings.

To allow agent process injection and inspection on selected host sets:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Custom Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Protect the agent process from injection and inspection to OFF.

  6. Click Save to save the policy settings.

To stop preventing unauthorized users and processes from tampering with agent files and folders:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Custom Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Prevent unauthorized users and processes from tampering with Trellix agent files and folders to OFF.

  6. Click Save to save the policy settings.

After creating your custom policy, you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

To disable strict certificate validation of xAgent files:

Important

The default value for this setting is ON. However, if you are experiencing PKI failure in your environment, you can use these steps to turn strict certificate validation off. Only endpoints running Endpoint Security (HX) xAgent version 34 or later can enable or disable strict certificate signing.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Perform strict certificate validation on agent binaries to OFF.

  6. Click Save to save the policy settings.