The AMSI module for Trellix Endpoint Security monitors, detects, and blocks suspicious scripts using the AMSI interface and generates alerts when malicious scripts are found.
The module compares scripts to YARA rules downloaded from the Trellix DTI. If any script matches a rule, the module sends the script objects for an additional Trellix Endpoint Security scan. An event with detection metadata is then sent to the Endpoint Security controller, and an alert is generated and displayed in the Alerts page.
The module is installed and enabled on host sets using the AMSI policy.