Enabling and disabling quarantine and malware protection processing exclusions

Prev Next

You can also optimize malware protection processing and performance on your host endpoints by globally applying the following quarantine exclusions to endpoints in your enterprise:

  • Exclude heuristic detections

  • Exclude adware

  • Exclude Potentially Unwanted Programs (PUP)

  • Exclude spyware

When these exclusion are enabled, the Trellix Endpoint Security (HX) xAgent malware protection engine will not quarantine or protect the host endpoint from malware detected using heuristic detections, adware, PUP, or spyware.

This section includes the following topics:

Excluding heuristic detections from malware protection processing

The Endpoint Security (HX) xAgent malware protection engine uses heuristics-based detection to identify previously unknown zero day malware on your host endpoints. You can enable and disable the heuristic detections exclusion from quarantine and malware protectihon processing for all of your host sets using the agent default policy. You can also exclude heuristic detections from quarantine and malware protection processing for specific host sets in your environment using a custom exclusion policy.

Important

Malware protection processing (malware detection) and quarantine must be enabled, or the heuristic detection exclusion is ignored.

This section covers how to use the Web UI to exclude heuristic detections from quarantine and malware protection processing. See the Endpoint Security (HX) REST API Guide for information on using the API to exclude heuristic detections from quarantine and malware protection processing.

Enabling the Heuristic Detections Exclusion
To enable heuristic detections exclusion for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Verify that malware detection and quarantine are enabled by ensuring that the Signature and Heuristic Detection ON/OFF switch and the Quarantine switch are both set to ON.

    Important

    Malware detection (Signature and Heuristic Detection) and quarantine must be enabled, or quarantine exclusions are ignored.

    Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

  6. Locate Quarantine Exclusions and select the Exclude Heuristic Detections from Quarantine and Other Protection Actions option to enable heuristic detections exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_Heuristic.png
  7. Click Save.

To enable heuristic detections exclusion for select host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Verify that malware detection and quarantine are enabled by ensuring that the Signature and Heuristic Detection ON/OFF switch and the Quarantine switch are both set to ON.

    Important

    Malware detection (Signature and Heuristic Detection) and quarantine must be enabled, or quarantine exclusions are ignored.

    Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

  6. Locate Quarantine Exclusions and select the Exclude Heuristic Detections from Quarantine and Other Protection Actions option to enable heuristic detections exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_Heuristic.png
  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling the Heuristic Detections Exclusion
To disable heuristic detections exclusion for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Locate Quarantine Exclusions and clear the Exclude Heuristic Detections from Quarantine and Other Protection Actions option to disable heuristic detections exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_QExcl_Heuristic_Disable.png
  6. Click Save.

To disable heuristic detections exclusion for select host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Locate Quarantine Exclusions and clear the Exclude Heuristic Detection from Quarantine and Other Protection Actions option to disable heuristic detections exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_QExcl_Heuristic_Disable.png
  6. Click Save.

Excluding Adware from malware protection processing

You can enable and disable the adware exclusion from quarantine and malware protection processing for all of your host sets using the xAgent default policy. You can also exclude adware from quarantine and malware protection processing for specific host sets in your environment using a custom exclusion policy.

Important

Malware protection processing (malware detection) and quarantine must be enabled, or the adware exclusion is ignored.

This section covers how to use the Web UI to exclude adware from quarantine and malware protection processing. See the Endpoint Security (HX) REST API Guide for information on using the API to exclude adware from quarantine and malware protection processing.

Enabling the Adware Exclusion
To enable adware exclusion for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Verify that malware detection and quarantine are enabled by ensuring that the Signature and Heuristic Detection ON/OFF switch and the Quarantine switch are both set to ON.

    Important

    Malware detection (Signature and Heuristic Detection) and quarantine must be enabled, or quarantine exclusions are ignored.

    Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

  6. Locate Quarantine Exclusions and select the Exclude Adware from Quarantine and Other Protection Actions option to enable adware exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_Adware.png
  7. Click Save.

To enable adware exclusion for select host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Verify that malware detection and quarantine are enabled by ensuring that the Signature and Heuristic Detection ON/OFF switch and the Quarantine switch are both set to ON.

    Important

    Malware detection (Signature and Heuristic Detection) and quarantine must be enabled, or quarantine exclusions are ignored.

    Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

  6. Locate Quarantine Exclusions and select the Exclude Adware from Quarantine and Other Protection Actions option to enable adware exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_Adware.png
  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling the Adware Exclusion
To disable Adware exclusion for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Locate Quarantine Exclusions and clear the Exclude Adware from Quarantine and Other Protection Actions option to disable adware exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_QExcl_Heuristic_Disable.png
  6. Click Save.

To disable Adware exclusion for select host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Locate Quarantine Exclusions and clear the Exclude Adware from Quarantine and Other Protection Actions option to disable Adware exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_Adware.png
  6. Click Save.

Excluding Potentially Unwanted Programs (PUP) from Malware Protection Processing

You can enable and disable the PUP exclusion from quarantine and malware protection processing for all of your host sets using the agent default policy. You can also exclude PUP from quarantine and malware protection processing for specific host sets in your environment using a custom exclusion policy.

Important

Malware protection processing (malware detection) and quarantine must be enabled, or the PUP exclusion is ignored.

This section covers how to use the Web UI to exclude PUP from quarantine and malware protection processing. See the Endpoint Security (HX) REST API Guide for information on using the API to exclude PUP from quarantine and malware protection processing.

Enabling the PUP Exclusion
To enable PUP exclusion for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Verify that malware detection and quarantine are enabled by ensuring that the Signature and Heuristic Detection ON/OFF switch and the Quarantine switch are both set to ON.

    Important

    Malware detection (Signature and Heuristic Detection) and quarantine must be enabled, or quarantine exclusions are ignored.

    Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

  6. Locate Quarantine Exclusions and select the Exclude PUP from Quarantine and Other Protection Actions option to enable PUP exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_PUP.png
  7. Click Save.

To enable PUP exclusion for select host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Verify that malware detection and quarantine are enabled by ensuring that the Signature and Heuristic Detection ON/OFF switch and the Quarantine switch are both set to ON.

    Important

    Malware detection (Signature and Heuristic Detection) and quarantine must be enabled, or quarantine exclusions are ignored.

    Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

  6. Locate Quarantine Exclusions and select the Exclude PUP from Quarantine and Other Protection Actions option to enable PUP exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_PUP.png
  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling the PUP Exclusion
To disable PUP exclusion for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Locate Quarantine Exclusions and clear the Exclude PUP from Quarantine and Other Protection Actions option to disable PUP exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_QExcl_PUP_Disable.png
  6. Click Save.

To disable PUP exclusion for select host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Locate Quarantine Exclusions and clear the Exclude PUP from Quarantine and Other Protection Actions option to disable PUP exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_QExcl_PUP_Disable.png
  6. Click Save.

Excluding Spyware from Malware Protection Processing

You can enable and disable the spyware exclusion from quarantine and malware protection processing for all of your host sets using the agent default policy. You can also exclude spyware from quarantine and malware protection processing for specific host sets in your environment using a custom exclusion policy.

Important

Malware protection processing (malware detection) and quarantine must be enabled, or the spyware exclusion is ignored.

This section covers how to use the Web UI to exclude spyware from quarantine and malware protection processing. See the Endpoint Security (HX) REST API Guide for information on using the API to exclude spyware from quarantine and malware protection processing.

Enabling the Spyware Exclusion
To enable spyware exclusion for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Verify that malware detection and quarantine are enabled by ensuring that the Signature and Heuristic Detection ON/OFF switch and the Quarantine switch are both set to ON.

    Important

    Malware detection (Signature and Heuristic Detection) and quarantine must be enabled, or quarantine exclusions are ignored.

    Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

  6. Locate Quarantine Exclusions and select the Exclude Spyware from Quarantine and Other Protection Actions option to enable spyware exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_Spyware.png
  7. Click Save.

To enable spyware exclusion for select host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Verify that malware detection and quarantine are enabled by ensuring that the Signature and Heuristic Detection ON/OFF switch and the Quarantine switch are both set to ON.

    Important

    Malware detection (Signature and Heuristic Detection) and quarantine must be enabled, or quarantine exclusions are ignored.

    Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

  6. Locate Quarantine Exclusions and select the Exclude Spyware from Quarantine and Other Protection Actions option to enable spyware exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_Quarantine_Spyware.png
  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling the Spyware Exclusion
To disable spyware exclusion for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Locate Quarantine Exclusions and clear the Exclude Spyware from Quarantine and Other Protection Actions option to disable spyware exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_QExcl_Spyware_Disable.png
  6. Click Save.

To disable spyware exclusion for select host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Locate Quarantine Exclusions and clear the Exclude Spyware from Quarantine and Other Protection Actions option to disable spyware exclusions from quarantine and malware protection processing.

    UI_Policy_MalProtect_QExcl_Spyware_Disable.png
  6. Click Save.