Modules overview

Prev Next

Modules are additional capabilities that you can add to your Endpoint Security (HX) Web UI and deliver directly to an assigned host set. When you install a module, new policies are added to Endpoint Security (HX). If a module provides detection capabilities, the results appear in your existing alert workflow.

Some modules, called System modules, are included with the Endpoint Security (HX) product. These modules and are enabled by default and cannot be disabled or uninstalled. You can install additional modules directly from DTI by using the Additional Modules tab or you can click the Find Modules button to access the Trellix Market, where you can download the configuration file for a module then upload the file to your Endpoint Security (HX) Web UI.

Each of the modules available on Trellix Market has its own User Guide, which is also available for download from the same Trellix Market page as the module. Typically, modules are initially available on a Tech Preview basis. In subsequent releases, these modules are then offered for General Availability.

After you install and enable a module, the module appears in the Modules menu in the Web UI. You can directly access a module by clicking it in the Modules menu, or by clicking Endpoint Module Administration.

Endpoint Module Administration is a user interface (UI) on which you can manage all aspects of your modules. It provides access to the Modules page, which contains separate tabs for System Modules, Installed Modules, and Available Modules. You can use the Modules page to view a list of all of the modules installed on your Web UI, install or uninstall additional modules, enable or disable installed modules, upgrade modules when a new version becomes available, set a module as your Dashboard, and access the Web UI pages for the individual modules listed on the page.

Some modules have both a server component and an agent component. You use the Endpoint Module Administration page to configure the server component of the module and you configure the agent component as part of the agent policy, which you can access from the Admin menu.

Caution

If you are disabling a module that has an agent component and a server component, you must disable the agent component on every policy to which it has been attached before you use the Endpoint Module Administration page to disable the server component of the module.