The key features of Threat Prevention protect against threats entering your environment, detect malware in your environment, and correct issues by cleaning or repairing infected files.
Protect
Protect your systems from intrusions before they gain access to your environment using these Threat Prevention features.
Access Protection — Protect against unwanted changes to client systems by restricting access to specified files, shares, registry keys, registry values, and preventing or restricting processes and services from executing threat behavior.
Exploit Prevention — Threat Prevention uses signatures in content updates to protect against these exploits:
Note
Exploit Prevention is not supported in the ARM architecture.
Buffer Overflow Protection — Stop exploited buffer overflows from executing arbitrary code.
Illegal API Use — Protect against malicious API calls being made by unknown or compromised applications running on the system.
Network Intrusion Prevention (Network IPS) — Protect against network denial-of-service attacks and bandwidth-oriented attacks that deny or degrade network traffic.
Expert Rules — Provide additional parameters and allow more flexibility than the Access Protection custom rules. But, to create Expert Rules, you must understand the Trellix proprietary syntaxes.
Command line interface — Run Full Scan, Quick Scan, custom on-demand scans, and update security content from the command line or as part of a batch file.
Detect
Detect threats when they occur in your environment using these Threat Prevention features.
On-Access Scan — Scan for threats as files are read from, or written to, disk. Integrates with Antimalware Scan Interface (AMSI) to provide enhanced scanning for threats in non-browser-based scripts.
On-Demand Scan — Run or schedule predefined scans, including scans of spyware-related registry entries that weren't previously cleaned. Run scans only when the system is idle. Restrict CPU usage to optimize scan performance.
Potentially Unwanted Programs — Detect potentially unwanted programs, such as spyware and adware, and prevent them from running in your environment.
Quarantine — Quarantine infected items, attempt to clean or repair them, or automatically delete them.
Dashboards and monitors — Display statistics about Threat Prevention, including scan duration, content update status, and applications with the most exploits. (Managed systems)
Queries and reports — Retrieve detailed information about Threat Prevention, including threat count, scan completion, detection response, false positive mitigation events, and Trellix GTI sensitivity level. (Managed systems)
Early Launch Anti-Malware — Support the ELAM feature included with Windows 8 and later releases. ELAM collects the list of device drivers loaded during the boot cycle and scans them once the scanning services are running.
Correct
Correct security issues, handle detections, improve performance, and enhance protection using these Threat Prevention features.
Actions — Take the specified action when detections occur.
Alerts — Notify when detections occur and limit traffic with filters.
Extra.DAT files — Protect against new threats, such as a major virus outbreak. Trellix ePO - On-prem
Scheduled scans — Run scans during nonpeak times to improve system and scan performance.
Content repositories — Reduce network traffic over the enterprise Internet or intranet by moving the content file repository closer to client systems. (Managed systems)
Log files (Trellix Endpoint Security (ENS) Client) — Provide a history of detected items, which you can use to determine if you need to change settings to enhance protection or improve system performance.
Dashboards and monitors — Review activity and use that information to tune Threat Prevention settings. (Managed systems)