With Dynamic Application Containment, you can specify that applications with specific reputations run in a container, limiting the actions they can perform. If the application reputation is at or below the containment reputation threshold, the application is contained.
Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.
Open the Trellix Endpoint Security (ENS) Client.
Click Adaptive Threat Protection on the main Status page.
Or, from the Action menu
, select Settings, then clickAdaptive Threat Protection on the Settings page.Click Show Advanced.
Click Options.
Verify that ATP is enabled.
Select Trigger Dynamic Application Containment when reputation threshold reaches.
Specify the reputation threshold at which to contain applications.
Might Be Trusted
Unknown (default for the Security rule group)
Might Be Malicious (default for the Balanced rule group)
Most Likely Malicious (default for the Productivity rule group)
Known Malicious
The Dynamic Application Containment reputation threshold must be above the block and clean thresholds. For example, if the block threshold is set to Known Malicious, the Dynamic Application Containment threshold must be set to Most Likely Malicious or above.
Click Apply.