AAC operates from the Windows kernel and can block access to network, file, registry, and process objects. Use AAC rules to determine what to block and allow.
AAC rules can describe unsafe behaviors that must be blocked or denied.
AAC rules can be:
Enabled or disabled
Set to Report only
Modified to add other processes to protect or to protect against
Excluded to no longer block a certain process from violating the rule
Some rules are not exposed in the interface because they are critical to the operational health of the product.
AAC sees an operation that is attempting to run and follows this process.
.png)
If a validation check fails or produces an untrusted result, Trellix internal protections might block Trellix processes from accessing objects.