The key features of Host Intrusion Prevention protect against threats, detect security issues, and correct false positives.
Protect
Protect your network and applications these Host Intrusion Prevention features:
Rules — Define the criteria Host Intrusion Prevention uses to determine whether to block or allow incoming and outgoing traffic.
Rule groups — Organize firewall rules for easy management, enabling you to apply rules manually or on a schedule, and to only process traffic based on connection type.
Stateful packet filtering and inspection — Track network connection state and characteristics in a state table, allowing only packets that match a known open connection.
Firewall Activity Logging — Trellix Endpoint Security (ENS) for Linux Host Intrusion Prevention now supports both allowed and blocked traffic.
Detect
Detect security issues using these Host Intrusion Prevention features:
Queries and reports — Retrieve detailed information about Host Intrusion Prevention, including client rules, errors, intrusion and block events, and save that information in reports.
Log traffic — Log all blocked or allowed traffic.
Correct
Reduce or eliminate false positives using these Host Intrusion Prevention features:
Adaptive mode — Create rules automatically on the client system to allow legitimate activity.
Once created, analyze client rules to decide which to convert to server-mandated policies.
Defined networks — Define trusted networks to allow traffic from networks that your organization considers safe.
Firewall Catalog — Define rules and groups to add to multiple policies, or networks and applications to add to firewall rules.
Client options — Allow users to disable Host Intrusion Prevention temporarily for troubleshooting.
Dashboards and monitors — Monitor activity and intrusion detections, then use that information to tune Host Intrusion Prevention settings.
For the comparison of Trellix Endpoint Security (ENS) for Host Intrusion Prevention features supported on Windows, Linux, and macOS, see Trellix Knowledge Base article KB85005.