mfetpcli is a command-line tool to execute tasks, and configure Trellix Endpoint Security (ENS) for Linux Threat Prevention settings.
You can use the mfetpcli command on standalone and managed systems. For managed systems, the configurations that you set using the command line is overwritten during the policy enforcement.
Before accessing the command-line Help, we recommend that you get familiar with these basic terminologies used in the Help.
Process type
Threat Prevention lets you define single On-Access Scan settings for all processes or different settings for each process type such as Standard, High Risk, and Low Risk.
Process
Threat Prevention determines the risk level based on the process (program) through which you access the file. When you access a file, Threat Prevention identifies the process used to access the file, verifies the risk level defined for that process, then applies the settings that are applicable for the process type. You can define a process as a high risk or low risk. If the process is not defined in either of the category, the process type is set to Standard process. When the process type is set to Use Standard settings for all process, all processes are treated as Standard processes.
For example, your organization might consider accessing unknown files through websites can expose your systems to threats. To protect your systems from such threats, you can add the browser software Chrome to the High Risk process, and configure settings specifically.
You can add, edit, or remove the process to the risk-based process as required using the command line. For more information about adding, changing, or removing the process to process category, see Define settings for a process.
Index
Index is a unique number by which mfetpcli identifies a task or process from the list.
When you create multiple on-demand scan tasks, the tasks are listed by its sequence number. You can identify the scan task by its unique number which is called as Index.
.png)
For example, this list contains two on-demand scan schedules. To run the task on-demand scan task KTods, from your custom path or the default path /opt/McAfee/ens/tp/bin, you must execute the command:
./mfetpcli --runtask --index 2