exploitDetection Section Settings

Prev Next

The exploitDetection settings provide keys that define how Exploit Guard is configured.

Select a setting from the table below to go to the edit methods Trellix supports. Some of the settings listed in this table can also be changed manually for an individual host by modifying the agent configuration file.

Setting Key

Default

Supported Edit Methods

Web UI

CLI

API

alertThreshold

---

No

No

No

appList

---

No

No

No

enable_notification

false

Yes

No

Yes

enable_pageguard

true

No

No

No

enable_prevent_known

false

Yes

No

Yes

enable_production

true

Yes

No

Yes

enable_protection

false

Yes

No

Yes

enable_server_os

false

No

No

No

enable_termination

false

Yes

No

Yes

excludedFiles

---

Yes

No

Yes

excludedMD5s

---

Yes

No

Yes

excludedPaths

---

Yes

No

Yes

rules_uri

/content/v1/intel/exd/rules

No

No

No

traceLevel

---

Yes

No

Yes

whitelist_uri

/content/v1/intel/exd/whitelist

No

No

No