Manual upgrade from Endpoint Security (HX) to EDRF

Prev Next

EDRF allows you to upgrade policies from Endpoint Security (HX) and retain your custom policy configurations.

To manually upgrade Endpoint Security (HX) policies to EDRF policies:

  1. Log in to the ePO server.

  2. Go to MenuPolicyPolicy Catalog.

  3. From the product list, select Trellix EDR with Forensics.

  4. Identify the existing Endpoint Security (HX) policy you want to upgrade, and locate the corresponding EDRF policy.

    For example, if Endpoint Security (HX) policies are associated with the General category in EDRF, create a new General policy in EDRF and customize its settings.

  5. Expand the applicable EDRF policy, and in the Actions column, click Edit.

  6. Customize the policy settings to align with your existing Trellix EDR policy framework.

  7. Save the updated policy.

The following table maps Endpoint Security (HX) policies to their corresponding categories within the EDRF policy framework. To implement these policies in EDRF, you must create a new policy within each mapped category.

Endpoint Security (HX) Policy

Mapping EDRF Policies Field

Endpoint Agent Console - 1.1.3 Section

NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu

Enable the Agent Console on the host

NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu

Event Log → Delete events from the Event Log that are older than

NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu

Quarantine → Allow Users The Ability To Restore Files From Quarantine

NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu

Quarantine → Allow Users The Ability To Delete Files From Quarantine

NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu

Malware Scans

Protection

Malware Scans

On-Demand Malware Scans

Scan on Install

Scan on Install

Scheduled Scans

You can create the scheduled scans using ePO Client tasks

Scheduled Scan

You can create the scheduled scans using ePO Client tasks

Scan Name

You can create the scheduled scans using ePO Client tasks

Time or Event

You can create the scheduled scans using ePO Client tasks

Depth

You can create the scheduled scans using ePO Client tasks

Scan Settings

Scan Settings

User Cancelled Scans

User Cancelled Scans

User Paused Scans

User Paused Scans

Pause duration - Days:Hours:Minutes: Seconds

Pause duration in minutes

Note

You need to convert it into minutes to configure it in EDRF.

Pause limit(per scan)

Pause limit(per scan) in seconds

Polling

General → HX Server → Server Polling

Poll agents - Hours: Minutes: Seconds

Poll interval in Seconds

Note

You need to convert it into seconds to configure it in EDRF.

Fastpoll agents - Hours: Minutes: Seconds

Fastpoll interval in Seconds

Note

You need to convert it into seconds to configure it in EDRF.

Proxy

General → Proxy Settings for Trellix EDR with Forensics

Proxy

Enable Proxy

Proxy Settings - Operating System or User Defined. If User Defined then the following fields are shown

Proxy Settings - Operating System or User Defined. If User Defined then the following fields are shown

Proxy name

Proxy name

Port

Port

Excluded hosts (use ';' as separator)

Excluded hosts (use ';' as separator)

Exclude Local/Simple Host Names

Exclude Local/Simple Host Names

Username

Username

Password

Password

Retry Delay in minutes

Retry Delay in minutes

Quarantine

Protection → Quarantine

Quarantine File Aging Section

Delete files from quarantine that are older than in day(s)

Delete files from quarantine that are older than in day(s)

Real-Time Indicator Detection

Detection → Real-Time Indicator Detection

Real-Time Indicator Detection is turned

Enable Real-Time Indicator Detection

Events sub-section

Events sub-section

Capture UDP Events

Capture UDP Events

Capture Network Connection Events

Capture Network Connection Events

Capture DNS Events

Capture DNS Events

Capture URL Events

Capture URL Events

Indicator Updates > Update indicators every - Hour:Minutes: Seconds

Update indicators every _ minutes

Note

You need to convert the number in minutes.

Linux RTE Sensor Health Port

NA. Currently using different sensor

Exclude Files or Folders

Exclusions

Exclude files or folders from Real-Time indicator Detection

Exclude file(s) or folder(s) from Real-Time indicator Detection (Use ';' as separator) (max:3072 characters)

Exclude Processes from the Real-time Indicator Detection

Exclude Process(es) from Real-Time indicator Detection

Exclude process(es) from Real-Time indicator Detection (Use ';' as separator) (max:3072 characters)

Exclude Registry Keys from Real-Time indicator Detection

Exclude Registry Keys from Real-Time indicator Detection

Select Hive

Select Hive

Enter key path

Enter key path

Optional value(s)

Optional value(s) (Use ',' as separator)

Removal Protection

General → Self-Protection

Enable Protection

Enable password to uninstall

Password

Enter password

Confirm password

Resource Use

General → Performance Management

Acquisition CPU usage limit (Minimum of 10%)

Acquisition CPU usage limit (Minimum of 10%)

Auto Triage

It is enabled by default

Event storage (10-500 MB)

Event storage (10-500 MB)

Storage mode

Storage mode

Priority Scheduling

Priority Scheduling

Concurrent Host Limit

NA - In EDRF Client, it is by default set and managed

Limit concurrent tasks to a given number of Hosts

NA - In EDRF Client, it is by default set and managed

Server Address

General → Forensics (HX) Server

Enter server address of appliance(s)

In EDRF, you need to add it in the Server settings. For more information, see Add the Endpoint HX server to ePO SaaS.

Once you configure the Endpoint Security (HX) server, you can select the server of your choice in the Registered Forensics(HX)servers list.

Registered Forensics (HX) servers

Server Polling

Poll interval in seconds

Fastpoll interval in seconds

Malware Detection

Protection

Signature and Heuristic Detection

Signature and Heuristic Detection

Cloud lookup

Cloud lookup

MalwareGuard Detection

MalwareGuard Detection

Cloud lookup

Cloud lookup

Malware Detection

Malware Detection

Scan Network Files

Scan network files

Scan on file read-only

Scan on file read-only

Scan on file write only

Scan on file write only

Scan on both file read and write

Scan on both files read and write

Malware Definition Updates

Update Malware Definition Rules

By default it is 2 hrs

Malware Definition Source

Default value is Endpoint Security (HX) Server

Content Backup

Content Backup

Enable AV Content Backup

Enable AV Content Backup

Content Exclusion List

Content Exclusion List

Policy Exclusions

Policy Exclusions

Exclude processes from malware scanning

Exclude processes from malware scanning (Use ';' as separator) (max:3072 characters)

Exclude files or folders from malware scanning

Exclude files or folders from malware scanning (Use ';' as separator) (max:3072 characters)

Exclude hashes from malware scanning

Exclude hashes from malware scanning (Use ';' as separator) (max:3072 characters)

MalwareGuard Content Update

MalwareGuard Content Download Timeout - Hours:Minutes: Seconds

Quarantine

Quarantine

Signature and Heuristic Quarantine

Signature and Heuristic Quarantine

MalwareGuard Quarantine

MalwareGuard Quarantine

Quarantine Action

Quarantine Action

Clean Infections From Files (Once Quarantined)

Clean infections from files (once quarantined)

Remove Malware Traces (Once Quarantined)

Remove malware traces (once quarantined)

Notify The Users On The Host When A File Has Been Quarantined Or Cleared

Notify the users on the host when a file has been quarantined or cleared

Quarantine Malicious Archives

Quarantine malicious archives

Quarantine Exclusions

Quarantine Exclusions

Exclude Heuristic Detection From Quarantine And Other Protection Actions

Exclude Heuristic Detection from quarantine and other protection actions

Exclude Adware From Quarantine And Other Protection Actions

Exclude Adware from quarantine and other protection actions

Exclude PUP From Quarantine And Other Protection Actions

Exclude PUP from quarantine and other protection actions

Exclude Spyware From Quarantine And Other Protection Actions

Exclude Spyware from quarantine and other protection actions

Forensics Bridge

NA - The necessary components for EDRF functionality are integrated within the EDRF Client, eliminating the need for additional configurations.

Enable Forensic Bridge

NA. The necessary components for EDRF functionality are integrated within the EDRF Client, eliminating the need for additional configurations.

Send Alerts to ePO Section

IOC

Malware Protection

AMSI

Logon Tracker

Agent Logging

General → Forensics (HX) Server

Alert Logging

Enable logging

Agent log level

Log level

Log Storage

Log Storage

by event count number of events (10,000 to 5,000,000)

By event count, the number of events (10,000 to 5,000,000)

by calendar days __ Days (1-365)

by calendar days __ Days (1-365)

Separate log per module

Separate log per module

Component Logging

General → Component Logging

Calls to libuv read and write

Calls to libuv read and write

SSL functions

SSL functions

Internal queue usage

Internal queue usage

Job-related

Job-related

Agent Health

General → Trellix EDR with Forensics Health

Report agent health status

Report agent health status

Reporting interval __ minutes

Reporting interval __ minutes

Tamper Protection

General → Enable Self-Protection

Deny local permission to Stop and Restart agent services.

General → Enable Self-Protection

Protect select agent processes from injection, inspection, and termination.

Prevent unauthorized users and processes from tampering with Trellix Agent files and folders.

Perform strict certificate validation on agent binaries

Detect unsigned image loads

WinTrust Verification Section

Verify SIP Provider

Verify Trust Provider

Verify Binary

Audits

Enabled by default

Configure Protect features

The Protect features included in the forensics capabilities of the Endpoint Security (HX) modules are available in Trellix Endpoint Security (ENS). This section explains how to configure the protection features of Trellix Endpoint Security (ENS).

As a prerequisite, you must first deploy Trellix Endpoint Security (ENS) on your endpoints. For details, see Install Trellix Endpoint Security (ENS) 10.7.x for the first time.

Use the Policy Catalog in ePO to configure the required protection capabilities in Trellix Endpoint Security (ENS).

Configure Threat Prevention

Use Threat Prevention policies in Trellix Endpoint Security (ENS) to configure file scanning and detection controls

  1. Log in to Trellix ePO.

  2. Navigate to MenuPolicyPolicy Catalog and select Endpoint Security Threat Prevention.

  3. From the On-access category, select a policy and click Edit.

  4. In the On-access Scan section, select Enable.

  5. If you use Trellix GTI, select Enable Trellix GTI, and click Save.

Configure Access Protection

Use Access Protection in Trellix Endpoint Security (ENS) to configure protection against exploit-based activities.

  1. In Trellix ePO, navigate to MenuPolicyPolicy Catalog and select Endpoint Security Threat Prevention.

  2. From the Access Protection category, select a policy and click Edit.

  3. Click Show Advanced. In the Rules section, select Block or Report for a predefined rule.

    Note

    When a rule is triggered, Report sends a notification only. Block prevents the activity.

  4. Click Save.

Configure Exploit Prevention

Use Exploit Prevention in Trellix Endpoint Security (ENS) to configure protection against exploit-based activities.

  1. In Trellix ePO, navigate to MenuPolicyPolicy Catalog and select Trellix Endpoint Security (ENS) from the Products list.

  2. From the Exploit Prevention category, select a policy and click Edit.

  3. The Enable Exploit Prevention option under the Exploit Prevention section is enabled by default. Unselect the checkbox to disable it.

  4. Navigate to the Signatures section.

    This includes a list of predefined signatures, enabled for High and Medium severity.

    Tip

    Enable 6000 signatures for optimum performance.

  5. In the Block and Report columns, seven signatures for LSASS are enabled by default. To disable a signature, clear the checkbox for that specific row.

    Note

    The Block and Report columns are enabled by default for High severity signatures.

  6. Enable the Additional Configuration to use these options:

    • Enable Generic Privilege Escalation Prevention

    • Enable Windows Data Execution Prevention

    • Enable Windows Data Execution Prevention

  7. Navigate to Policy Catalog home page and select Endpoint Security Adaptive Threat Protection.

  8. From the Options category, select a policy and click Edit.

  9. In the ML Protect Scanning (Windows only) section, select the Enable Credential Theft Protection checkbox to block credential theft from unknown processes.

Configure Antimalware Scan Interface (AMSI)

Use AMSI in Trellix Endpoint Security (ENS) to enable script scanning capabilities.

  1. In Trellix ePO, navigate to MenuPolicyPolicy Catalog and select Trellix Endpoint Security (ENS).

  2. From the On-access category, select a policy and click Edit.

  3. In the Antimalware Scan Interface (Windows only) section, verify if the Enable AMSI (provides enhanced script scanning) (Windows only) option is selected.

  4. Navigate to the Policy Catalog home page and select Endpoint Security Adaptive Threat Protection.

  5. From the Options category, select a policy and click Edit.

  6. In the ML Protect Scanning (Windows only) section, verify if the Enable enhanced script scanning (includes AMSI integration) option is selected. Unselect the checkbox to disable it.

    Note

    Enable Observe Mode is enabled by default. In this mode, actions are not enforced on events. To enter protection mode and enforce actions, clear the checkbox.

Configure Exploit Prevention

Use Exploit Prevention in Endpoint Security (ENS) to configure protection against exploit-based activities.

  1. In Trellix ePO, navigate to MenuPolicyPolicy Catalog and select Trellix Endpoint Security (ENS) from the Products list.

  2. The Enable Exploit Prevention option under the Exploit Prevention section is enabled by default. Unselect the checkbox to disable it.

  3. Navigate to the Signatures section.

    This includes a list of predefined signatures, enabled for High and Medium severity.

    Tip

    Enable 6000 signatures for optimum performance.

Configure File Reputation

Use File Reputation controls to manage file trust levels and enforcement behavior.

As a prerequisite, make sure you deploy Trellix Threat Intelligence Exchange (TIE) on your endpoints. For details, see Threat Intelligence Exchange (TIE) 4.7.x Installation Guide.

  1. In Trellix ePO, go to MenuSystemsTIE Reputations and select File Overrides.

  2. Configure a custom reputation or import a reputation using the Import Reputation option.

  3. Click OK.

For details, see the Importing file reputations.

Tip

You can configure a File Reputation using Trellix Application and Change Control. For details, see Trellix Application and Change Control product guide.

Configure Device Control

Use Device Control policies to manage removable media and data transfer rules.

As a prerequisite, make sure you deploy Trellix Data Loss Prevention on your endpoints. For details, see Trellix Data Loss Prevention Endpoint 11.12.x Installation Guide.

  1. In Trellix ePO, go to MenuData ProtectionDLP Policy Manager and select Rule Sets.

  2. Click Actions to configure a custom Rule Set. You can refer to the built-in rule sets samples

    Select the Show built-in rule sets samples option to view the rule sets for reference.

  3. Click Save.

For details, see Create a rule set.