The first line of defense against malware is to protect your client systems from threats. Access Protection protects files, registry keys, registry values, processes, and services. Exploit Prevention prevents buffer overflow, illegal API use, and network exploits.
Trellix delivers Trellix-defined signatures in Exploit Prevention content updates. When the content file is updated, the signatures are updated if needed.
Access protection
Access protection prevents unwanted changes to client systems by restricting access to specified files, shares, registry keys, registry values, and preventing or restricting processes and services from executing threat behavior.
Access protection uses both Trellix-defined rules (signatures) and user-defined rules (also called custom rules) to report or block access to items. Access Protection compares a requested action against the list of rules and acts according to the rule.
You can also create Expert Rules to restrict access to files, registry keys, registry values, processes, and services, using Trellix-provided syntax templates.
You can create expert rules to stop buffer overflow and illegal API use exploits.
Note
With Microsoft Window 8.1 and later, Access Protection rules no longer support operations for the Services subrule type. This is because Microsoft made services.exe a protected process in Windows 8.1 and later.
Buffer Overflow and Illegal API Use
Buffer overflow protection stops exploited buffer overflows from executing arbitrary code. This technology monitors applications in the application protection list and uses signatures in the Exploit Prevention content file to protect those applications. Exploit Prevention monitors user-mode API calls and recognizes when they are called as a result of a buffer overflow.
Illegal API use monitors the Windows Application Programming Interface (API) and protects against malicious API calls being made by unknown or compromised applications running on the system.
You can create Expert Rules to stop buffer overflow and illegal API use exploits, using Trellix-provided syntax templates.
You can create expert rules to stop buffer overflow and illegal API use exploits.
You can view Buffer Overflow and Illegal API Use events in Trellix ePO - On-prem on the Exploit Prevention Events page under Reporting.
Network IPS
Network Intrusion Prevention (Network IPS) protects against network denial-of-service attacks and bandwidth-oriented attacks that deny or degrade network traffic. Network IPS examines all data that flows between the client system and the rest of the network and compares it to the Trellix Network IPS signatures. When an attack is identified, the offending data is discarded or blocked from passing through the system.
You can't create Network IPS custom rules or Expert Rules.
Note
Host Intrusion Prevention 8.0 can be installed on the same system as Endpoint Security version 10.7. If the Host IPS or Network IPS options in Host IPS are enabled, Exploit Prevention and Network Intrusion Prevention are disabled even if enabled in the Threat Prevention settings.