Enabling exploit termination

Prev Next

To enable the option to terminate exploited processes for all host endpoints in the xAgent default policy:

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the  link to access the Edit Policy page.

  4. Select the Exploit Guard tab.

  5. In the Exploit Guard Options section, select Terminate the exploited process. When this option is selected, exploited processes are terminated when they are detected.

    Policy_ExG_Terminate.png

  6. To quarantine any blocked exploit documents and scripts from running on your host endpoint, you can also select Quarantine malicious artifacts.

  7. Click Save.

To enable the option to terminate exploited processes for all selected host endpoints in a custom policy:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Exploit Guard tab.

  5. In the Exploit Guard Options section, select Terminate the exploited process. When this option is selected, exploited processes are terminated when they are detected.

    Policy_ExG_Terminate.png

  6. To quarantine any blocked exploit documents and scripts from running on your host endpoint, you can also select Quarantine malicious artifacts.

  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.