The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Protect files, registry, processes, and services with Access Protection rules on a client system

Prev Next

Change the behavior of Trellix-defined rules or create custom rules to protect your system access points.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Tip

Best practice: For information about creating Access Protection rules to protect against ransomware, see KB89335, and KB89540.

Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Threat Prevention on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Threat Prevention on the Settings page.

  3. Click Show Advanced.

  4. Click Exploit Prevention.

    Note

    Exploit Prevention is not supported in the ARM architecture.

  5. Change a Trellix-defined rule: In the Rules section, double-click the rule.

    1. On the Edit Trellix-defined Rule page, configure the settings.

    2. In the Executables section, click Add, configure the settings, then click Save twice to save the rule.

  6. Create a custom rule: In the Rules section, click Add.

    1. On the Add Rule page, configure the settings.

    2. In the Executables section, click Add, configure executable properties, then click Save.

      The executable is the process that performs the subrule operation on the subrule target.

      An empty Executables table indicates that the rule applies to all executables.

    3. In the User Names section, click Add, then configure user name properties.

      An empty User Names table indicates that the rule applies to all users.

    4. In the Subrules section, click Add, then configure subrule properties.

      Note

      With Microsoft Window 8.1 and later, Access Protection rules no longer support operations for the Services subrule type. This is because Microsoft made services.exe a protected process in Windows 8.1 and later.

    5. In the Targets section, click Add, configure target information, then click Save twice.

  7. Specify the behavior of the rule:

    In the Rules section, select Block, Report, or both for the rule.

    • To block or report all, select Block or Report in the first row.

    • To disable the rule, deselect both Block and Report.

  8. Click Apply.