EDRF allows you to upgrade policies from Endpoint Security (HX) and retain your custom policy configurations.
To manually upgrade Endpoint Security (HX) policies to EDRF policies:
Log in to the ePO server.
Go to Menu → Policy → Policy Catalog.
From the product list, select Trellix EDR with Forensics.
Identify the existing Endpoint Security (HX) policy you want to upgrade, and locate the corresponding EDRF policy.
For example, if Endpoint Security (HX) policies are associated with the General category in EDRF, create a new General policy in EDRF and customize its settings.
Expand the applicable EDRF policy, and in the Actions column, click Edit.
Customize the policy settings to align with your existing Trellix EDR policy framework.
Save the updated policy.
The following table maps Endpoint Security (HX) policies to their corresponding categories within the EDRF policy framework. To implement these policies in EDRF, you must create a new policy within each mapped category.
Endpoint Security (HX) Policy | Mapping EDRF Policies Field |
|---|---|
Endpoint Agent Console - 1.1.3 Section | NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu |
Enable the Agent Console on the host | NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu |
Event Log → Delete events from the Event Log that are older than | NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu |
Quarantine → Allow Users The Ability To Restore Files From Quarantine | NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu |
Quarantine → Allow Users The Ability To Delete Files From Quarantine | NA - Trellix Agent → Allow end users to update security from the Trellix system tray menu |
Malware Scans | Protection |
Malware Scans | On-Demand Malware Scans |
Scan on Install | Scan on Install |
Scheduled Scans | You can create the scheduled scans using ePO Client tasks |
Scheduled Scan | You can create the scheduled scans using ePO Client tasks |
Scan Name | You can create the scheduled scans using ePO Client tasks |
Time or Event | You can create the scheduled scans using ePO Client tasks |
Depth | You can create the scheduled scans using ePO Client tasks |
Scan Settings | Scan Settings |
User Cancelled Scans | User Cancelled Scans |
User Paused Scans | User Paused Scans |
Pause duration - Days:Hours:Minutes: Seconds | Pause duration in minutes
|
Pause limit(per scan) | Pause limit(per scan) in seconds |
Polling | General → HX Server → Server Polling |
Poll agents - Hours: Minutes: Seconds | Poll interval in Seconds
|
Fastpoll agents - Hours: Minutes: Seconds | Fastpoll interval in Seconds
|
Proxy | General → Proxy Settings for Trellix EDR with Forensics |
Proxy | Enable Proxy |
Proxy Settings - Operating System or User Defined. If User Defined then the following fields are shown | Proxy Settings - Operating System or User Defined. If User Defined then the following fields are shown |
Proxy name | Proxy name |
Port | Port |
Excluded hosts (use ';' as separator) | Excluded hosts (use ';' as separator) |
Exclude Local/Simple Host Names | Exclude Local/Simple Host Names |
Username | Username |
Password | Password |
Retry Delay in minutes | Retry Delay in minutes |
Quarantine | Protection → Quarantine |
Quarantine File Aging Section | |
Delete files from quarantine that are older than in day(s) | Delete files from quarantine that are older than in day(s) |
Real-Time Indicator Detection | Detection → Real-Time Indicator Detection |
Real-Time Indicator Detection is turned | Enable Real-Time Indicator Detection |
Events sub-section | Events sub-section |
Capture UDP Events | Capture UDP Events |
Capture Network Connection Events | Capture Network Connection Events |
Capture DNS Events | Capture DNS Events |
Capture URL Events | Capture URL Events |
Indicator Updates > Update indicators every - Hour:Minutes: Seconds | Update indicators every _ minutes
|
Linux RTE Sensor Health Port | NA. Currently using different sensor |
Exclude Files or Folders | Exclusions |
Exclude files or folders from Real-Time indicator Detection | Exclude file(s) or folder(s) from Real-Time indicator Detection (Use ';' as separator) (max:3072 characters) |
Exclude Processes from the Real-time Indicator Detection | |
Exclude Process(es) from Real-Time indicator Detection | Exclude process(es) from Real-Time indicator Detection (Use ';' as separator) (max:3072 characters) |
Exclude Registry Keys from Real-Time indicator Detection | Exclude Registry Keys from Real-Time indicator Detection |
Select Hive | Select Hive |
Enter key path | Enter key path |
Optional value(s) | Optional value(s) (Use ',' as separator) |
Removal Protection | General → Self-Protection |
Enable Protection | Enable password to uninstall |
Password | Enter password |
Confirm password | |
Resource Use | General → Performance Management |
Acquisition CPU usage limit (Minimum of 10%) | Acquisition CPU usage limit (Minimum of 10%) |
Auto Triage | It is enabled by default |
Event storage (10-500 MB) | Event storage (10-500 MB) |
Storage mode | Storage mode |
Priority Scheduling | Priority Scheduling |
Concurrent Host Limit | NA - In EDRF Client, it is by default set and managed |
Limit concurrent tasks to a given number of Hosts | NA - In EDRF Client, it is by default set and managed |
Server Address | General → Forensics (HX) Server |
Enter server address of appliance(s) | In EDRF, you need to add it in the Server settings. For more information, see Add the Endpoint HX server to ePO SaaS. |
Once you configure the Endpoint Security (HX) server, you can select the server of your choice in the Registered Forensics(HX)servers list. | |
Registered Forensics (HX) servers | |
Server Polling | |
Poll interval in seconds | |
Fastpoll interval in seconds | |
Malware Detection | Protection |
Signature and Heuristic Detection | Signature and Heuristic Detection |
Cloud lookup | Cloud lookup |
MalwareGuard Detection | MalwareGuard Detection |
Cloud lookup | Cloud lookup |
Malware Detection | Malware Detection |
Scan Network Files | Scan network files |
Scan on file read-only | Scan on file read-only |
Scan on file write only | Scan on file write only |
Scan on both file read and write | Scan on both files read and write |
Malware Definition Updates | |
Update Malware Definition Rules | By default it is 2 hrs |
Malware Definition Source | Default value is Endpoint Security (HX) Server |
Content Backup | Content Backup |
Enable AV Content Backup | Enable AV Content Backup |
Content Exclusion List | Content Exclusion List |
Policy Exclusions | Policy Exclusions |
Exclude processes from malware scanning | Exclude processes from malware scanning (Use ';' as separator) (max:3072 characters) |
Exclude files or folders from malware scanning | Exclude files or folders from malware scanning (Use ';' as separator) (max:3072 characters) |
Exclude hashes from malware scanning | Exclude hashes from malware scanning (Use ';' as separator) (max:3072 characters) |
MalwareGuard Content Update | |
MalwareGuard Content Download Timeout - Hours:Minutes: Seconds | |
Quarantine | Quarantine |
Signature and Heuristic Quarantine | Signature and Heuristic Quarantine |
MalwareGuard Quarantine | MalwareGuard Quarantine |
Quarantine Action | Quarantine Action |
Clean Infections From Files (Once Quarantined) | Clean infections from files (once quarantined) |
Remove Malware Traces (Once Quarantined) | Remove malware traces (once quarantined) |
Notify The Users On The Host When A File Has Been Quarantined Or Cleared | Notify the users on the host when a file has been quarantined or cleared |
Quarantine Malicious Archives | Quarantine malicious archives |
Quarantine Exclusions | Quarantine Exclusions |
Exclude Heuristic Detection From Quarantine And Other Protection Actions | Exclude Heuristic Detection from quarantine and other protection actions |
Exclude Adware From Quarantine And Other Protection Actions | Exclude Adware from quarantine and other protection actions |
Exclude PUP From Quarantine And Other Protection Actions | Exclude PUP from quarantine and other protection actions |
Exclude Spyware From Quarantine And Other Protection Actions | Exclude Spyware from quarantine and other protection actions |
Forensics Bridge | NA - The necessary components for EDRF functionality are integrated within the EDRF Client, eliminating the need for additional configurations. |
Enable Forensic Bridge | NA. The necessary components for EDRF functionality are integrated within the EDRF Client, eliminating the need for additional configurations. |
Send Alerts to ePO Section | |
IOC | |
Malware Protection | |
AMSI | |
Logon Tracker | |
Agent Logging | General → Forensics (HX) Server |
Alert Logging | Enable logging |
Agent log level | Log level |
Log Storage | Log Storage |
by event count number of events (10,000 to 5,000,000) | By event count, the number of events (10,000 to 5,000,000) |
by calendar days __ Days (1-365) | by calendar days __ Days (1-365) |
Separate log per module | Separate log per module |
Component Logging | General → Component Logging |
Calls to libuv read and write | Calls to libuv read and write |
SSL functions | SSL functions |
Internal queue usage | Internal queue usage |
Job-related | Job-related |
Agent Health | General → Trellix EDR with Forensics Health |
Report agent health status | Report agent health status |
Reporting interval __ minutes | Reporting interval __ minutes |
Tamper Protection | General → Enable Self-Protection |
Deny local permission to Stop and Restart agent services. | General → Enable Self-Protection |
Protect select agent processes from injection, inspection, and termination. | |
Prevent unauthorized users and processes from tampering with Trellix Agent files and folders. | |
Perform strict certificate validation on agent binaries | |
Detect unsigned image loads | |
WinTrust Verification Section | |
Verify SIP Provider | |
Verify Trust Provider | |
Verify Binary | |
Audits | Enabled by default |
Configure Protect features
The Protect features included in the forensics capabilities of the Endpoint Security (HX) modules are available in Trellix Endpoint Security (ENS). This section explains how to configure the protection features of Trellix Endpoint Security (ENS).
As a prerequisite, you must first deploy Trellix Endpoint Security (ENS) on your endpoints. For details, see Install Trellix Endpoint Security (ENS) 10.7.x for the first time.
Use the Policy Catalog in ePO to configure the required protection capabilities in Trellix Endpoint Security (ENS).
Configure Threat Prevention
Use Threat Prevention policies in Trellix Endpoint Security (ENS) to configure file scanning and detection controls
Log in to Trellix ePO.
Navigate to Menu → Policy → Policy Catalog and select Endpoint Security Threat Prevention.
From the On-access category, select a policy and click Edit.
In the On-access Scan section, select Enable.
If you use Trellix GTI, select Enable Trellix GTI, and click Save.
Configure Access Protection
Use Access Protection in Trellix Endpoint Security (ENS) to configure protection against exploit-based activities.
In Trellix ePO, navigate to Menu → Policy → Policy Catalog and select Endpoint Security Threat Prevention.
From the Access Protection category, select a policy and click Edit.
Click Show Advanced. In the Rules section, select Block or Report for a predefined rule.
Note
When a rule is triggered, Report sends a notification only. Block prevents the activity.
Click Save.
Configure Exploit Prevention
Use Exploit Prevention in Trellix Endpoint Security (ENS) to configure protection against exploit-based activities.
In Trellix ePO, navigate to Menu → Policy → Policy Catalog and select Trellix Endpoint Security (ENS) from the Products list.
From the Exploit Prevention category, select a policy and click Edit.
The Enable Exploit Prevention option under the Exploit Prevention section is enabled by default. Unselect the checkbox to disable it.
Navigate to the Signatures section.
This includes a list of predefined signatures, enabled for High and Medium severity.
Tip
Enable 6000 signatures for optimum performance.
In the Block and Report columns, seven signatures for LSASS are enabled by default. To disable a signature, clear the checkbox for that specific row.
Note
The Block and Report columns are enabled by default for High severity signatures.
Enable the Additional Configuration to use these options:
Enable Generic Privilege Escalation Prevention
Enable Windows Data Execution Prevention
Enable Windows Data Execution Prevention
Navigate to Policy Catalog home page and select Endpoint Security Adaptive Threat Protection.
From the Options category, select a policy and click Edit.
In the ML Protect Scanning (Windows only) section, select the Enable Credential Theft Protection checkbox to block credential theft from unknown processes.
Configure Antimalware Scan Interface (AMSI)
Use AMSI in Trellix Endpoint Security (ENS) to enable script scanning capabilities.
In Trellix ePO, navigate to Menu → Policy → Policy Catalog and select Trellix Endpoint Security (ENS).
From the On-access category, select a policy and click Edit.
In the Antimalware Scan Interface (Windows only) section, verify if the Enable AMSI (provides enhanced script scanning) (Windows only) option is selected.
Navigate to the Policy Catalog home page and select Endpoint Security Adaptive Threat Protection.
From the Options category, select a policy and click Edit.
In the ML Protect Scanning (Windows only) section, verify if the Enable enhanced script scanning (includes AMSI integration) option is selected. Unselect the checkbox to disable it.
Note
Enable Observe Mode is enabled by default. In this mode, actions are not enforced on events. To enter protection mode and enforce actions, clear the checkbox.
Configure Exploit Prevention
Use Exploit Prevention in Endpoint Security (ENS) to configure protection against exploit-based activities.
In Trellix ePO, navigate to Menu → Policy → Policy Catalog and select Trellix Endpoint Security (ENS) from the Products list.
The Enable Exploit Prevention option under the Exploit Prevention section is enabled by default. Unselect the checkbox to disable it.
Navigate to the Signatures section.
This includes a list of predefined signatures, enabled for High and Medium severity.
Tip
Enable 6000 signatures for optimum performance.
Configure File Reputation
Use File Reputation controls to manage file trust levels and enforcement behavior.
As a prerequisite, make sure you deploy Trellix Threat Intelligence Exchange (TIE) on your endpoints. For details, see Threat Intelligence Exchange (TIE) 4.7.x Installation Guide.
In Trellix ePO, go to Menu → Systems → TIE Reputations and select File Overrides.
Configure a custom reputation or import a reputation using the Import Reputation option.
Click OK.
For details, see the Importing file reputations.
Tip
You can configure a File Reputation using Trellix Application and Change Control. For details, see Trellix Application and Change Control product guide.
Configure Device Control
Use Device Control policies to manage removable media and data transfer rules.
As a prerequisite, make sure you deploy Trellix Data Loss Prevention on your endpoints. For details, see Trellix Data Loss Prevention Endpoint 11.12.x Installation Guide.
In Trellix ePO, go to Menu → Data Protection → DLP Policy Manager and select Rule Sets.
Click Actions to configure a custom Rule Set. You can refer to the built-in rule sets samples
Select the Show built-in rule sets samples option to view the rule sets for reference.
Click Save.
For details, see Create a rule set.