Enabling Tamper Protection for all host endpoints

Prev Next

If the Tamper Protection policy has been disabled for all of your host endpoints, you can enable it by modifying the agent default policy. This prevents your system administrators from stopping or restarting the xAgent services and protect the xAgent process from injection and inspection on all of your Windows hosts.

To prevent the stop and restart of xAgent services on all host endpoints:

Important

When the Tamper Protection policy is enabled through the Agent Default Policy, only Windows endpoints running Endpoint Security (HX) xAgent version 29 or later will prevent the stop and restart of agent services on all host endpoints.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Deny local admin permission to Start and Stop to ON.

  6. Click Save to save the policy settings.

To protect xAgent processes from injection and inspection on all host endpoints:

Important

When the Tamper Protection policy is enabled through the Agent Default Policy, only Windows endpoints running Endpoint Security (HX) xAgent version 20 or later will protect the xAgent process from injection and inspection on all host endpoints.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Protect the agent process from injection and inspection to ON.

  6. Click Save to save the policy settings.

To prevent unauthorized users and processes from tampering with agent files and folders:

Important

When the Tamper Protection policy is enabled through the Agent Default Policy, only Windows endpoints running Endpoint Security (HX) xAgent version 33 or later will prevent unauthorized users from tampering with files and folders.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Prevent unauthorized users and processes from tampering with Trellix agent files and folders to ON.

  6. Click Save to save the policy settings.

To enable strict certificate validation of xAgent files:

Important

The default value for this setting is ON. However, if you have previously turned strict certificate validation off, you can use these steps to turn it back on. Only endpoints running Endpoint Security (HX) xAgent version 34 or later can enable or disable strict certificate signing.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Perform strict certificate validation on agent binaries to ON.

  6. Click Save to save the policy settings.