Exploit guard protection

Prev Next

Trellix Endpoint Security (HX) products can monitor your host endpoints for previously unrecognized exploits and other online attacks using a feature called Exploit Guard Protection that provides both exploit detection and prevention.

Exploit Guard Protection is supported for host endpoints running in specific Windows environments only, including Windows Vista, 7, 8, 8.1, and 10. Exploit Guard Protection is not supported for host endpoints running macOS or Linux operating systems. For more information about the Windows, macOS, and Linux operating systems that support specific Endpoint Security (HX) xAgent versions, see "Operating System Requirements" in the Endpoint Security (HX) Server Deployment Guide.

Exploit detection uncovers exploit behaviors on your host endpoints that occur during the use of Adobe Reader, Adobe Flash, Internet Explorer, Firefox, Google Chrome, Java, Microsoft Outlook, Microsoft Word, Microsoft Excel, and Microsoft PowerPoint. The following are examples of the exploit types that can be detected in these applications.

  • Return-oriented programming (ROP) attacks

  • Reverse shell attempts in Windows environments

  • Heap spray attacks

  • Application crashes caused by exploits

  • Structured Exception Handling Overflow Protection (SEHOP) corruption

  • Drive-by downloads of programs

  • Null page exploits

  • Microsoft Office macro-based exploits

  • Java exploits

  • Access token privilege escalation detection

  • First stage shellcode detection

If activated, exploit prevention can block and even terminate monitored applications affected by an exploit. It can also notify you when an exploit has been prevented. By default, exploit detection is activated after you initially install xAgent software on your endpoints and exploit prevention is not. You can enable or disable Exploit Guard Protection completely by modifying the global default policy. See Configuring the Global Default Policy for more information.

Exploit Guard stores its intelligence in a rules file and uses an exclusion file to identify common files to be excluded from Exploit Guard processing. These files are supplied and maintained by Trellix only. The latest files can be downloaded from the DTI cloud.

Exploit detection is supported for Windows endpoints running Endpoint Security (HX) xAgent version 21 or later. Exploit prevention is supported for Windows endpoints running Trellix Endpoint Security (HX) xAgent version 22 or later.

Using the Endpoint Security (HX) Server Web UI, you can modify the global default policy and create a custom exclusion policy for Exploit Guard behavior. See Exploit Guard Overview and Defining the Exploit Guard Global Policy for additional information about Exploit Guard processing and about setting up these policies.