Change the behavior of Trellix-defined rules or create custom rules to protect your system access points.
Tip
For information about creating Access Protection rules to protect against ransomware, see KB89335 and KB89540.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.
From the Category list in the right pane, select Access Protection.
Click the Edit link for an editable policy.
Click Show Advanced.
Change a Trellix-defined rule: In the Rules section, select the rule, then click Edit.
On the Rule page, configure rule options.
In the Executables section, click Add, configure executable properties, then click Save twice to save the rule.
Create a custom rule: In the Rules section, click Add.
On the Rule page, configure the settings.
In the Executables section, click Add, configure executable properties, then click Save. An empty Executables table indicates that the rule applies to all executables.
In the User Names section, click Add, configure user name properties, then click Save.
In the Subrules section, click Add, then configure subrule properties.
Note
With Microsoft Window 8.1 and later, Access Protection rules no longer support operations for the Services subrule type. This is because Microsoft made services.exe a protected process in Windows 8.1 and later.
In the Targets section, click Add, configure target information, then click Save three times.
Specify the behavior of the rule: In the Rules section, select Block, Report, or both for the rule.
To select or deselect all rules under Block or Report, click Block All or Report All.
To disable the rule, deselect both Block and Report.
Click Save.
Important
Registry READ operations are very expensive in terms of system resources and performance. These rules should only be used in emergency situations due to the expected performance issues that can occur and are not intended for general use.