Attack Surface Reduction (ASR) provides proactive defense by identifying threats based on their content and activity patterns rather than just known signatures. You can enable managed ASR rules to detect ransomware behavior and bait file creation attempts during on-access scans without requiring complex expert rules.
Tip
For a complete list of Attack Surface Reduction (ASR) content that can be enabled using Expert Rules, see KB93741.
Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.
Open the Trellix Endpoint Security (ENS) Client.
Click Threat Prevention on the main Status page.
Or, from the Action menu
, select Settings, then click Threat Prevention on the Settings page.Select the following checkboxes to enable protections:
Detect unknown ransomware based on behaviour – Enables the rule to identify processes exhibiting ransomware-like activity.
Create ransomware bait files on file system – Enables the rule to block the creation of files commonly associated with ransomware attacks.
Click Apply.