Trellix Endpoint Security (HX) can monitor your host endpoints for previously unrecognized exploits and other online attacks using a feature called Exploit Guard that provides both exploit detection and prevention.
Exploit detection detects exploit behaviors on your host endpoints that occur during the use of Adobe Reader, Adobe Flash, Microsoft Edge, Firefox, Chrome, Java, and Microsoft Office applications, such as Excel, Powerpoint, and Word. The following are examples of the exploit types that can be detected in these applications.
Return-oriented programming (ROP) attacks
Reverse shell attempts in Windows environments
Heap spray attacks
Application crashes caused by exploits
Structured Exception Handling Overflow Protection (SEHOP) corruption
Drive-by downloads of programs
Null page exploits
Microsoft Office macro-based exploits
Java exploits
Access token privilege escalation detection
First stage shellcode detection
Exploit detection is disabled by default. You must enable it on the Policies page. You should add all of your exclusions before enabling this feature.
Exploit prevention can block, terminate, and even quarantine monitored applications affected by an exploit. End users can be notified when an exploit is prevented.
Exploit Guard stores its intelligence in a rules file and uses an exclusion file to identify common files to be excluded from Exploit Guard processing. These files are supplied and maintained by Trellix only. The latest files can be downloaded from the DTI cloud.
Exploit detection is supported for Windows endpoints running Trellix Endpoint Security (HX) xAgent version 21 or later. Exploit prevention is supported for Windows endpoints running Trellix Endpoint Security (HX) xAgent version 22 or later.
You can use the Endpoint Security (HX) Web UI to create policies that specify Exploit Guard behavior and apply the policies to host sets. For additional information about Exploit Guard processing and about setting up these policies, see the Endpoint Security Agent (HX) Administration Guide.