The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Key features of Adaptive Threat Protection

Prev Next

The key features of ATP protect your enterprise from files with unknown reputations, detect malicious patterns, and correct false positives.

Protect

Protect your enterprise by blocking or containing files with unknown reputations using these ATP features:

  • Reputation-based file handling — ATP alerts when an unknown file enters the environment.

    Instead of sending the file information to Trellix for analysis, ATP can block the file immediately.

  • Integration with the TIE server — If available, the TIE server provides information about how many systems ran the file. Sandbox server helps determine whether the file is a threat.

  • Dynamic Application Containment — Allows unknown files to run in a container, limiting the actions they can take.

    When a company first uses a file whose reputation is not known, ATP can run it in a container. Containment rules define which actions the contained application can't perform. Dynamic Application Containment also contains processes when they load PE files (Portable Executables) and DLLs (Dynamic Link Libraries) that downgrade the process reputation.

Detect

Detect malicious patterns and malware in memory using these ATP features:

  • ML Protect scanning — Performs automated behavior analysis.

    ML Protect inspects suspicious files and activities on a client system and detects malicious patterns using machine-learning techniques. ML Protect client-based and cloud-based scans include DLL scanning to keep trusted processes from loading untrusted PE and DLL files.

  • Credential Theft Protection — Protects against credential theft.

    The credential theft protection technology is designed to cease attacks specifically targeting the Local Security Authority Subsystem Service (LSASS).

    Note

    Credential Theft Protection (CTP) is not supported in the ARM architecture.

  • Enhanced script scanning — Integration with AMSI (Antimalware Scan Interface) provides enhanced scanning for threats in non-browser-based scripts, such as PowerShell, JavaScript, and VBScript.

  • ATP rules — Determines what processes can and can't do within a specific context and can change reputation based on the context and behavior.

Correct

Clean files and eliminate false positives using these ATP features:

  • File cleaning — ATP can clean files when the file reputation reaches a specified threshold.

  • Enhanced remediation — If a process is unknown, enhanced remediation monitors its behavior and logs all files that the process creates and, optionally, all files that the process changes or deletes. If a monitored process exhibits malicious behavior, enhanced remediation stops the process, its children, and ancestors, and rolls back the changes that it made, restoring the system as close as possible to its original state before the process ran.

  • Custom file exclusions — If a custom file is trusted, but has a default reputation of malicious, it is blocked. You can exclude it from scanning or change the file's reputation to trusted and allow it to run in the organization without requesting an updated DAT file from Trellix.

  • False positive mitigation:

    • If ATP gets a file reputation above a certain threshold from the TIE server or Trellix GTI, it can automatically override a false positive detection by Adaptive Threat Protection or Threat Prevention.

    • If Adaptive Threat Protection determines that a detection is a false positive, Trellix Advanced Research Center might release a negative Extra.DAT file to suppress the detection until the next content update.

  • Adaptive Threat Protection rulesTrellix delivers updates to rules in AMCore content every month.

  • Trellix ePO - On-prem Dashboards and reports — Show activity and detections, which you can use to tune Adaptive Threat Protection settings. (Managed systems)