The Exploit Guard Protection policy tab allows you to define Exploit Guard behaviors for all agents in your environment. You can access the Exploit Guard Protection tab in the xAgent default policy and in any custom policy that has the Exploit Guard policy category selected.
.png)
Note
The Exploit Guard Protection policy tab applies to Trellix Endpoint Security (HX) xAgent s version 22 and later in Windows environments only. It does not apply to agents running on macOS or Linux endpoints.
The Exploit Guard Protection tab shows the following information:
Whether Exploit Guard Protection is enabled or disabled
Enabled or disabled Exploit Guard options
Exploit Guard policy exclusions for host sets assigned to the policy
Note
Exploit detection requires Trellix Endpoint Security (HX) xAgent version 21 or later. Exploit prevention requires version 22 or later. Host endpoints running earlier Endpoint Security (HX) xAgent versions do not support the global and exception policies for exploit detection and prevention.
ON/OFF switch
The Exploit Guard ON/OFF switch allows you to enable or disable Exploit Guard processing (exploit detection and exploit prevention) for all host endpoints assigned to a specific policy.
Exploit Guard options section
Exploit Guard settings in the apply to all hosts in your enterprise, except host sets assigned to a custom policy that modifies Exploit Guard settings or a custom policy that excludes select host sets from Exploit Guard processing.
The exploit prevention options Prevent known suspicious behaviors and Terminate the exploited process allow you to tailor exploit prevention behavior for host sets assigned to a specific policy. The Notify the user on the host when an exploit has been blocked option notifies you when an exploit is blocked.
Enabling the Terminate the exploited process option allows you to enable the Quarantine malicious artifacts option, which quarantines the blocked exploit documents or scripts from running on your host endpoint.
Important
Enabling exploit prevention may result in data loss when an exploit is blocked in an active process and exploit prevention terminates the process that started the infection.
Exploit Guard Policy exclusions section
The Exploit Guard Policy Exclusions section allows you to exclude monitored applications, files and folders, and MD5 hashes from Exploit Guard processing for all host sets in your enterprise. You can add global exclusions to the policy using the xAgent default policy or you can create a custom exclusion policy for specific host sets in your enterprise. See Defining Exploit Guard Protection Exclusion Policies for more information.
Policy Exclusions | Description |
|---|---|
Exclude monitored applications from Exploit Guard processing | This section allows you to exclude monitored applications from Exploit Guard processing for all assigned host sets. |
Exclude files and folders from Exploit Guard processing | This section allows you to exclude or whitelist files and folders from Exploit Guard processing for all assigned host sets. |
Exclude MD5 hashes from Exploit Guard processing | This section allows you to exclude or whitelist MD5 hashes from Exploit Guard processing for all assigned host sets. |