The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Overview of Threat Prevention

Prev Next

Trellix Endpoint Security (ENS) Threat Prevention blocks threats from accessing systems, scans files automatically when they are accessed, and runs targeted scans for malware on client systems.

Threat Prevention detects threats based on security content files. Security content updates are delivered automatically to target specific vulnerabilities and block emerging threats from executing.

Threat Prevention protects your environment from the following:

  • Viruses, worms, and trojan horses

  • Access point violations — unwanted changes to files, shares, registry keys, registry values, and preventing or restricting processes and services from executing threat behavior.

  • Buffer overflow exploits

  • Illegal API use — malicious API calls being made by unknown or compromised application

  • Network intrusions, such as network denial-of-service attacks and bandwidth-oriented attacks

  • Potentially unwanted code and programs

  • Vulnerability focused threats

  • Zero-day exploits

  • Threats in non-browser-based scripts, such as PowerShell, JavaScript, and VBScript

You use Trellix ePO - On-prem to deploy and manage Threat Prevention on client systems.