To enable exploit prevention for the xAgent default policy:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Exploit Guard Protection tab.
Verify that the Exploit Guard switch is ON.
.png)
Select at least one of the following options, depending on your system requirements.
Prevent known suspicious behaviors. See Blocking Exploited Processes.
Terminate the exploited process. See Terminating Exploited Processes.
Exploit prevention occurs if either of these options is selected.
Important
Enabling exploit prevention may result in data loss when an exploit is blocked in an active process and exploit prevention terminates the process that started the infection.
Click Save.
To enable exploit prevention for a custom policy:
Note
See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Exploit Guard Protection tab.
Verify that the Exploit Guard switch is ON.
.png)
Select at least one of the following options, depending on your system requirements.
Prevent known suspicious behaviors. See Blocking Exploited Processes.
Terminate the exploited process. See Terminating Exploited Processes.
Exploit prevention occurs if either of these options is selected.
Important
Enabling exploit prevention may result in data loss when an exploit is blocked in an active process and exploit prevention terminates the process that started the infection.
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.