The enable_termination key indicates whether the exploit prevention option to terminate monitored applications when exploits are detected has been enabled or not. Valid values are true (enabled) or false (disabled). The default is false.
If the enable_termination key value is true, set the following key values to true:
Change this setting using one of the following methods:
Web UI (see Terminating Exploited Processes ).
API custom configuration channels (see Using API Custom Configuration Channels).
Manually on individual endpoints using a text editor (see Modifying the Configuration File for a Single Endpoint).