The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Overview of Adaptive Threat Protection

Prev Next

Trellix Endpoint Security (ENS) Adaptive Threat Protection examines your enterprise content and decides what to do based on file reputation, rules, and reputation thresholds.

Adaptive Threat Protection provides these benefits:

  • Fast detection and protection against security threats and malware.

  • The ability to know which systems or devices are compromised, and how the threat spread through your environment.

  • The ability to immediately clean specific files based on their threat reputations and your risk criteria.

  • Integration with Machine Learning Protect (ML Protect) scanning to perform automated behavior analysis in the cloud and on client systems.

  • Credential Theft Protection (CTP) safeguards the Local Security Authority Subsystem Service (LSASS.exe) from potential hacker threats. Processes which unexpectedly attempt to access the Microsoft LSASS.exe process for credentials will have that action blocked and an event will be sent to Trellix ePO - On-prem.

    Note

    Credential Theft Protection (CTP) is not supported in the ARM architecture.

  • Enhanced script scanning, including integration with Antimalware Scan Interface (AMSI).

  • The ability to identify fileless attack methods in which no persistent malware file exists.

  • The ability to monitor unknown processes and automatically remediate changes to the system.

  • Real-time integration with Sandbox server, Adaptive Threat Protection, and Trellix Threat Intelligence Exchange (TIE) enables submission of unknown files during file creation and execution. This returns detailed file assessment and data on reputation and malware classification. The integration allows you to respond to threats and share the information throughout your environment.

For more threat intelligence sources and functionality, deploy the Trellix Threat Intelligence Exchange (TIE) server. For information, contact your reseller or sales representative.

Optional components

Adaptive Threat Protection can integrate with these optional components:

  • TIE server- A server that stores information about file and certificate reputations, and additional metadata, then shares that information with other systems.

  • Trellix DXL - Clients and brokers that enable bidirectional communication between the Adaptive Threat Protection module on the managed system and the Trellix Threat Intelligence Exchange (TIE) server.

These components include Trellix ePO - On-prem extensions that add several features and reports.