Exploit Guard

Prev Next

Trellix Endpoint Security (HX) can monitor your host endpoints for previously unrecognized exploits and other online attacks using a feature called Exploit Guard that provides both exploit detection and prevention.

Exploit detection detects exploit behaviors on your host endpoints that occur during the use of Adobe Reader, Adobe Flash, Microsoft Edge, Firefox, Chrome, Java, and Microsoft Office applications, such as Excel, Powerpoint, and Word. The following are examples of the exploit types that can be detected in these applications.

  • Return-oriented programming (ROP) attacks

  • Reverse shell attempts in Windows environments

  • Heap spray attacks

  • Application crashes caused by exploits

  • Structured Exception Handling Overflow Protection (SEHOP) corruption

  • Drive-by downloads of programs

  • Null page exploits

  • Microsoft Office macro-based exploits

  • Java exploits

  • Access token privilege escalation detection

  • First stage shellcode detection

Exploit detection is disabled by default. You must enable it on the Policies page. You should add all of your exclusions before enabling this feature.

Exploit prevention can block, terminate, and even quarantine monitored applications affected by an exploit. End users can be notified when an exploit is prevented.

Exploit Guard stores its intelligence in a rules file and uses an exclusion file to identify common files to be excluded from Exploit Guard processing. These files are supplied and maintained by Trellix only. The latest files can be downloaded from the DTI cloud.

Exploit detection is supported for Windows endpoints running Trellix Endpoint Security (HX) xAgent version 21 or later. Exploit prevention is supported for Windows endpoints running Trellix Endpoint Security (HX) xAgent version 22 or later.

You can use the Endpoint Security (HX) Web UI to create policies that specify Exploit Guard behavior and apply the policies to host sets. For additional information about Exploit Guard processing and about setting up these policies, see the Endpoint Security Agent (HX) Administration Guide.