The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Protecting Trellix processes from third-party DLLs

Prev Next

Software applications that run in Microsoft Windows environments can inject code into a third-party process. Trellix software considers third-party DLLs that are injected into Trellix processes to be untrusted because the code might be compromised or used maliciously.

Third-party DLL activity appears to originate from the injected Trellix process. If this activity is malicious, it looks like Trellix software is performing these malicious operations.

Trellix uses these technologies to protect against DLL injections:

  • Validation and Trust Protection (VTP) service — Inspects DLLs and running processes that interact with Trellix code to verify whether objects are trusted.

  • Arbitrary Access Control (AAC) rules — Determines whether to block or allow access to objects.