The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Test Exploit Prevention installation

Prev Next

From the policy, enable Exploit Prevention and update signature 50001 with block and report access. Apply the policy to the client machine.

  1. Run the command to check if Exploit Prevention is enabled or disabled.

    ./mfetpcli --getepstatus

  2. To check the status of signatures, run:

    ./mfetpcli --getallepsignatures

    Note

    Block and report status for signature ID 50001 should be shown as enabled.

  3. Use this command to check violation of the rule:

    touch/usr/bin/watchbog

You will see permission denied as the Block status is enabled. And the event is reported to ePO.