The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Exploit Prevention

Prev Next

Trellix Endpoint Security (ENS) for Linux supports Exploit prevention for Linux in a managed environment.

It brings in content support that can automatically define access control policies and settings for processes, files, and directories. By restricting access to specific files and directories, you can protect your systems from vulnerabilities. Content support brings in signatures that can automatically enforce the above policies and can be updated on a regular cadence. The individual signatures can then be managed from ePO and configured to block and report access.

For violations, you can either enable or disable reporting.

Note

Exploit Prevention is not supported in standalone systems.

Note

Trellix Endpoint Security (ENS) for Linux doesn't support expert rules for Exploit Prevention.