The combination of Threat Prevention, Firewall, Web Control and the Common module features stops malware and other security threats before they can infect your Mac systems.
Threat Prevention
Process based on-access scanning — Supports process based on-access scan configuration for Standard, High Risk, and Low Risk processes.
Shared Scan cache — Supports the Use the scan cache option in the Full Scan, Quick Scan, and Custom On-Demand Scan in the Threat Prevention policy. On-access scanners and on-demand scanners now utilize the cache to avoid scanning known clean files.
Support for Medium DAT — The product now supports Medium DAT (for content) that reduces the on-disk footprint of the product.
Enhancements in client user interface — Supports configuring process based on-access scanning, and displaying Full Scan and Quick Scan configuration in the client interface. Full Scan and Quick Scan configuration settings are displayed only on systems that are managed by ePO - On-prem.
Support for Apple Endpoint Security APIs — Threat Prevention and Adaptive Threat Protectionrun without kernel extension. By default, the software is installed with async mode. You can switch to sync mode as required for standalone and managed systems.
On-Access Scan — Scans files and directories for threats when users access them.
On-Demand Scan — Schedules a scan on files and directories at specific times. Each on-demand scan contains its own policy settings. You can also run Full Scan or Quick Scan on a Mac.
Trellix GTI — Supports Trellix GTI, a heuristic network lookup for suspicious files for on-access and on-demand scanning.
Policy-Based On-Demand Scan client tasks — Run a Quick Scan or Full Scan on the Trellix ENS client from ePO - On-prem. Configure the behavior of these scans in the policy settings for On-Demand Scan.
Product Update client tasks — Update the engine and content files automatically from the Trellix download website.
Extra.DAT files — Download and install Extra.DAT files provide protection from a major virus outbreak.
Scheduled tasks — Change client tasks (such as Product Update) and scan times to improve performance by running them during non-peak times.
Content repositories — Reduce network traffic over the enterprise Internet or intranet by moving the content file repository closer to the clients.
Scan policies — Analyze log files or queries and change policies to increase performance or virus protection, if needed. For example, you can improve performance by configuring exclusions.
Additional options when scheduling on-demand scans — Allows you to run an on-demand scan when the system is idle or not running on battery power.
Exclusion of files and directories from scanning — Excludes specific files and directories from on-access scanning and on-demand scanning using criteria such as file type, extension, file age, or wildcards.
Option to scan network volumes, compressed files, and Apple emails — Exclude or include mounted network volumes, compressed files, and Apple emails from scanning.
Option to retain client-side exclusions — Overwrites or retains the client exclusion list for on-access sc(dance)anning in a managed environment.
Firewall
Application-based Firewall protection — Allows you to create application-specific Firewall rule to allow or block network traffic for the application.
Regular mode — Executes the associated action defined in the rule, when the network packet adheres to a rule's condition. If no matching rule is found, the network packet is blocked.
Adaptive mode — Executes the associated action defined in the rule, when the network packet adheres to a rule's condition. If no matching rule is found, the network packet is allowed and a rule is created to allow similar packets later.
Stateful firewall — Validates each packet for different connections against predefined rules, holding the connection attributes in memory from beginning‑to‑end.
Domain Name System (DNS) blocking — Blocks access to networks that can include unwanted domains.
Defined networks — Defines networks including subnets, ranges, or a single IP address that can be used while creating firewall rules. You can also configure Firewall to trust networks.
Stateful FTP inspection — Creates dynamic rules automatically for FTP data connections, by actively monitoring the FTP commands on the control channel.
Location awareness — Creates separate rules for locations, such as office or home network.
Management of rules — Creates and manages rules using rule group.
Firewall events — Sends Allow and Block events to ePO - On-prem.
For the comparison of Trellix Endpoint Security (ENS) for Firewall features supported on Windows, Linux, and macOS, see Trellix Knowledge Base article KB85005.
Web Control
Support for Google Chrome browser — Protects your Mac from web-based threats, when you browse sites using the Google Chrome browser.
Safety ratings button — Displays the safety rating in the upper-left corner of the browser when you access the site. The color of the button indicates the risk associated with the site.
Search Annotation — Displays the safety rating icon next to each site listed by the search engine. The color of the icon indicates the risk associated with the site.
Note
The software supports only the Google search engine.
Web category blocking — Allows or denies access to sites based on their content type.
Block and Allow List — Creates a list of sites to allow or block based on URLs and domains.
Block phishing pages — Blocks access to phishing sites.
Logging events — Monitors and regulates browser activity and log events for:
Sites configured in the Block and Allow List
Web categories for green-rated sites
Red or yellow-rated site visits
Common Policy
Password protection for client interface — Allows you to configure different access levels for users as needed. You can also prevent users from changing the protection preferences.
Password protection for uninstallation — Allows you to set password protection for the client software to prevent removal of the software from the Mac.
Self-Protection — Protects security software files, folders, and processes from being modified or deleted by malware.
General
Support for FIPS 140-2 - Product components now use FIPS-capable OpenSSL cryptographic libraries to ensure secure communication and data protection.
Support for dark mode — The product interface now dynamically switches to the dark mode or light mode automatically according to the display mode you select.
Common extensions to manage Windows, Macintosh, and Linux systems — Use Trellix® Endpoint Security extensions as common extensions to manage policies for your Windows, Mac, and Linux systems.
CommonePO - On-prem Dashboard and queries — Use the ePO - On-prem dashboard to view the status of managed Mac and Windows systems.
Turn off protection using the command-line option during product deployment — You can disable Threat Prevention, Firewall using the command-line option from the ePO - On-prem server when deploying the software on managed Mac systems. For more information about using the command-line option, see Trellix Knowledge Base article KB85505.
Support for Trellix ePolicy Orchestrator - SaaS — Support for Trellix ePolicy Orchestrator - SaaS to manage policies for your Mac.
Option to select protection modules — You can install one or all protection modules on a standalone Mac as needed.
Trellix® Agent status monitor — Displays information, and initiates communication with ePO - On-prem manually from the managed system.
Menulet for easy access of the software interface — Easy access to the user interface by clicking the Trellix menulet from the status bar.
Enable debug logging from client interface — Enable debug logging for the modules that you have installed using the client interface.