The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Enable advanced ransomware behaviour detection on a client system

Prev Next

Attack Surface Reduction (ASR) provides proactive defense by identifying threats based on their content and activity patterns rather than just known signatures. You can enable managed ASR rules to detect ransomware behavior and bait file creation attempts during on-access scans without requiring complex expert rules.

Tip

For a complete list of Attack Surface Reduction (ASR) content that can be enabled using Expert Rules, see KB93741.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Threat Prevention on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Threat Prevention on the Settings page.

  3. Select the following checkboxes to enable protections:

    • Detect unknown ransomware based on behaviour – Enables the rule to identify processes exhibiting ransomware-like activity.

    • Create ransomware bait files on file system – Enables the rule to block the creation of files commonly associated with ransomware attacks.

  4. Click Apply.