Exploit Guard uses special detection heuristics to detect shellcode in its early stages.
The enable_pageguard key indicates whether these special detection heuristics should be enabled for use in Exploit Guard processing. Valid values are true (enabled) or false (disabled). The default is true.
Important
Trellix Endpoint Security (HX) xAgent version 25 and later automatically disables PageGuard when the Windows kernel debug option is enabled.
Note
Enabling the DEBUG option in Windows BCDEDIT interferes with this processing. Trellix recommends that you turn the DEBUG option off before you upgrade to Trellix Endpoint Security (HX) xAgent version 24 or later. If that is not possible, Trellix recommends that you disable the enable_pageguard setting.
Change this setting using one of the following methods:
API custom configuration channels (see Using API Custom Configuration Channels).
Manually on individual endpoints using a text editor (see Modifying the Configuration File for a Single Endpoint).
Caution
Do not change the value of this setting without the advice of your Trellix support representative.