The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Enable advanced ransomware behaviour detection using ePO

Prev Next

Attack Surface Reduction (ASR) provides proactive defense by identifying threats based on their content and activity patterns rather than just known signatures. You can enable managed ASR rules to detect ransomware behavior and bait file creation attempts during on-access scans without requiring complex expert rules.

Tip

For a complete list of Attack Surface Reduction (ASR) content that can be enabled using Expert Rules, see KB93741.

  1. In ePO, select MenuPolicyPolicy Catalog.

  2. Select Endpoint Security Threat Prevention, then select On-Access Scan.

  3. Select Edit in My Default policy.

  4. Locate the Ransomware Protections section, then select Add.

  5. Select the following checkboxes to enable protections:

    • Detect unknown ransomware based on behaviour – Enables the rule to identify processes exhibiting ransomware-like activity.

    • Create ransomware bait files on file system – Creates ransomware bait file and enables the rule to block the creation of files commonly associated with ransomware attacks.

  6. Select Save.