The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Responding to Exploit Prevention detections

Prev Next

When Exploit Prevention detects security violations, as defined by signatures or rules, it triggers events and sends them to the Trellix ePO - On-prem server.

Exploit Prevention Events page

Trellix ePO - On-prem displays buffer overflow and illegal API use events in the Exploit Prevention Events page under Reporting.

Review the list of events to determine which events are allowable and which indicate suspicious behavior. Under certain circumstances, behavior that is interpreted as an attack can be a normal part of a user’s work routine. When this occurs, you can create an exclusion for that behavior. Creating exclusions allows you to reduce false positive alerts, and helps ensure that the notifications you receive are meaningful.

In the Exploit Prevention Events page, you can:

  • Use filters to reduce the list to only those events that satisfy the filter criteria.

  • Aggregate events to generate a list of events grouped by the value associated with selected criteria.

  • Create exclusions from events.

Threat Event Log page

All Exploit Prevention events, including Network IPS events, appear in the Threat Event Log under Reporting with the events for all products managed by Trellix ePO - On-prem.