The spyware key allows you to enable and disable the spyware exclusion from Trellix Endpoint Security (HX) xAgent malware protection engine's quarantine and remediation actions. Valid values are true (enabled) or false (disabled).
When the spyware exclusion is enabled, the Trellix Endpoint Security (HX) xAgent malware protection engine does not quarantine or protect the host endpoint from spyware. By default, the spyware key is disabled.
If you set the spyware key value to true, you must also set the following key values to true:
malware Detection enable Key
Quarantine enable Malware Quarantine Key
Important
If these keys are not enabled, the
spywarekey value is ignored.
Change this setting using one of the following methods:
Web UI (see Excluding Spyware from Malware Protection Processing ).
API custom configuration channels (see Using API Custom Configuration Channels).
Manually on individual endpoints using a text editor (see Modifying the Configuration File for a Single Endpoint).