Endpoint Product Guide

Prev Next

Last Updated: November 27, 2025


Overview

Trellix Endpoint enhances Microsoft Windows Defender Antivirus and Microsoft Windows Defender Firewall allowing you to monitor potential threats on Windows endpoints. It provides monitoring support for Microsoft Windows 10 (version 1709 and later) and Microsoft Windows Server 2016 (and later).

Trellix Endpoint provides a range of threat detection and policy management capabilities including:

  • Centralized management for Windows Defender Antivirus and Windows Defender Firewall.

  • Policies defined inTrellix ePolicy Orchestrator - On-premises or Trellix ePolicy Orchestrator - SaaS are applied to Trellix Endpoint, and Windows Defender Antivirus and Windows Defender Firewall.

  • Threat alerts and the security compliance status of your endpoints are intuitively displayed, with filtering options available to provide information on specific threats and devices.

  • Protection Workspace, a centralized dashboard which monitors unresolved detections, escalated devices, and resolved threats on your managed endpoints.

  • Story Graph, a graphical tracing of endpoint threat detections which displays the process and file behavior that led to the detection.

Key features

Trellix Endpoint enhances protection on your Microsoft Windows 10 and Microsoft Windows Server 2016 (and later) endpoints.

Enhanced detection for Windows Defender Antivirus

Trellix Endpoint:

  • Provides enhanced analysis of the file when Windows Defender Antivirus allows a file to execute.

  • Uses local and cloud technologies to detect and provide protection against the threats that bypass Windows Defender Antivirus

  • Includes protection against credential harvesting. It provides static and behavioral protection.

  • Uses machine-learning research to analyze the latest zero-day threats.

  • IOAV protection scans files being downloaded and zipped files being extracted for threats.

Windows Defender Antivirus management

Trellix ePolicy Orchestrator - SaaS and Trellix ePolicy Orchestrator - On-premises:

  • Manage Trellix Endpoint.

  • Manage several Windows Defender Antivirus features when Trellix Endpoint is installed on your endpoints.

  • Provides reporting on all endpoints that have Windows Defender Antivirus active.

Windows Defender Firewall rule management

Trellix Endpoint:

  • Enables centralized management of Windows Defender Firewall and rule management from Trellix ePolicy Orchestrator - SaaS and Trellix ePolicy Orchestrator - On-premises.

  • Reports the number of blocked events from WIndows Defender Firewall in the past 24 hours.

  • Reports firewall compliance data from each managed endpoint and sends this information to Trellix ePolicy Orchestrator - SaaS and Trellix ePolicy Orchestrator - On-premises.

Note

Windows Defender Firewall and firewall rule management are switched off by default. Manage your Windows Defender Firewall rules by navigating to Policy Catalog > Firewall Rules.

Windows Defender Exploit Guard management

Trellix ePolicy Orchestrator - SaaS and Trellix ePolicy Orchestrator - On-premises:

  • Manage several Windows Defender Exploit Guard features.

  • Provide reporting on all endpoints that have Windows Defender Exploit Guard active.

Support for Windows 10 and Windows Server operating systems

Trellix Endpoint provides support and management of Windows Defender Antivirus, Windows Defender Firewall, and Windows Defender Exploit Guard on Windows 10 and Windows Server 2016 and later systems.

Protection Workspace

  • The Protection Workspace dashboard allows you to monitor threats in your network, view compliance information about Trellix products, and manage your devices. You can view information about:

    • The total number of devices managed by Trellix Endpoint

    • Devices tagged as Escalated

    • Resolved and unresolved threats

    • Quarantined threats

    • Endpoint compliance status

    • Graphical information about file behavior that led to its detection.

Unified policy model

Define policies for Windows Defender Antivirus, Windows Defender Firewall and Trellix Endpoint simultaneously, simplifying the management and protection of your endpoints.

How it works

Trellix Endpoint uses cloud content and local content to analyze data. It then presents the information in the Protection Workspace dashboard in ePO - On-prem.

Managing the Trellix Endpoint client component

The Trellix Endpoint client component is installed on each protected endpoint and communicates directly with your ePO - On-prem server.

  1. ePO - On-prem server (on-premises, in a hosted service, or Trellix ePolicy Orchestrator - SaaS).

  2. Trellix Endpoint sends file metadata to the cloud infrastructure for analysis.

  3. When files are quarantined, they are stored in the Quarantine database on the relevant endpoint. The server then reads from these endpoint quarantine locations to enable centralized quarantine management across all your protected endpoints and servers.

  4. When enabled, firewall rules are pushed to Windows Defender Firewall on the managed endpoints and servers.

  5. Summaries are sent to ePO - On-prem. These summaries include Windows Defender Firewall blocked events and firewall compliance data.

Note

When using Trellix Endpoint to manage Windows Defender Antivirus or Windows Defender Firewall, do not also use Domain Controller Group Policy or System Center Configuration Manager (SCCM) Policy. Domain Controller and SCCM policies have higher precedence and result in the Trellix Endpoint policies being overwritten.


How Trellix Endpoint works

Diagram showing Trellix Endpoint workflow. Left column: endpoints installed with Windows Defender AV, Firewall, and Trellix Endpoint client. Arrows illustrate steps to the cloud and orchestration boxes: 1) Analyze file metadata, 2) Quarantine the file, 3) Manage quarantine across all endpoints and servers, 4) Deploy firewall rules to endpoints, 5) Send firewall block events and compliance data. Diagram includes Trellix ePolicy Orchestrator on‑prem and Trellix ePolicy Orchestrator - SaaS boxes on the right.

Managing Windows Defender Antivirus

  1. Trellix Endpoint works with Windows Defender Antivirus

  2. Windows Defender Antivirus protects your endpoints and servers from known viruses and malware.

  3. Windows Defender Antivirus passes an executable to Trellix Endpoint for further analysis if it deems the executable to be safe. Trellix Endpoint then uses the Trellix local and cloud-based detection infrastructure for this more detailed analysis.

  4. Threat detections from Windows Defender Antivirus and Trellix Endpoint appear in the Protection Workspace where you can resolve threats and change your policies to refine your protection levels.

Note

Trellix Endpoint applies the Microsoft Defender policy when Tamper Protection is enabled. When enabled, Tamper Protection prevents Group Policy disabling some settings on Microsoft Defender. Because of this, Trellix Endpoint does not manage the following settings when Tamper Protection is enabled:

  • Real Time Monitoring

  • Behavior Monitoring

  • IOAV Protection

Trellix Endpoint applies Microsoft Defender policies on a best effort basis, and will try to apply all policies even if protected.

Windows Defender Antivirus and Trellix Endpoint can both quarantine files. You can manage quarantined files in the Quarantine Management area in ePO - On‑prem.


How Trellix Endpoint interacts with Windows Defender Antivirus

Diagram showing interaction flow between Windows Defender and Trellix Endpoint with numbered steps — 1) Windows Defender allows executable to run; 2) Trellix Endpoint checks reputation, scans, and blocks suspicious threats; 3) Results are sent to Trellix ePO; 4) Threat details are displayed in Protection Workspace


Managing Windows Defender Firewall rules

  • Trellix Endpoint lets you manage Windows Defender Firewall rules. These rules are used across your protected endpoints and servers.

  • With a default set of firewall rules available out-of-the-box, you can quickly implement these rules and push them to all your protected endpoints and servers.

  • You can create rules, or change the existing ones, to meet your corporate requirements.

  • When creating rules, consider re-creating any previous firewall rules to maintain your current level of protection.

  • As an administrator, you can allow local firewall rules to be run on the endpoints and servers.


How Trellix Endpoint interacts with Windows Defender Firewall

Diagram showing the interaction flow between Trellix Endpoint and Windows Defender Firewall. The diagram is a numbered流程 with icons and dashed arrows illustrating steps: 1) Windows Defender Firewall rule management is enabled; 2) Firewall rules are deployed to endpoints; 3) Windows Defender uses the rules to block or allow connections to the endpoint; and 4) Firewall block events are sent to Trellix ePO.


View Trellix Endpoint features in the interface

ePO - On-prem extensions and components are used to access Trellix Endpoint features.

Security administrators define policies in ePO - On-prem which are pushed to Trellix Endpoint installed on your endpoint devices. As a result, Trellix Endpoint is used to manage your Microsoft Windows Defender Antivirus settings.

Protection Workspace

The Protection Workspace is the interface for Trellix Endpoint where you can view threat incidents and device compliance. It is included by default in ePO - SaaS, and is available as an extension for earlier versions of ePO - On-prem.


Protection Workspace interface showing Trellix Endpoint data

Trellix Protection Workspace dashboard screenshot showing multiple panels — threat overview, escalated devices, resolved threats, software status, and device management — arranged in a three-column dashboard layout.


Quarantine Management

The Quarantine Management extension allows you to manage quarantined files from any of your protected endpoints protected by Trellix Endpoint.

The Quarantine Management interface is located under System Tree. A Quarantine Content tab is found under the device information.

Automatic updating of client components

The Trellix Endpoint Updater extension allows you to automatically update your endpoints with the latest version of Trellix Endpoint. The Trellix Endpoint Update task runs daily by default, and updates your endpoints with the latest software from the ePO - On-prem Software Catalog.

Manage Trellix Endpoint with policies

Trellix Endpoint ships with default policies found in the ePO - On-prem Policy Catalog. These provide templates for you to create policies that match your organizational priorities.

Trellix Endpoint uses the following policy types: General, Firewall Rules,Exclusions, and Exploit Protection Program Settings. Follow the standard ePO - On-prem workflow to duplicate and change these policies as needed.

Note

As new features are added to Trellix Endpoint, new default policies are added to include updated settings. We recommend you use the latest versions as the basis for the policies pushed to your endpoints and servers.

Group Policy Enforcement status

Group Policy must be enforced for management of your endpoints using policies. The Group Policy Enforcement status can be viewed on your endpoints by navigating to System Tree and selecting an endpoint. Click Products > Trellix Endpoint and under General see Group Policy Enforcement Status.

If the status displays "Group Policy enforcement failed", restart the endpoint.

Trellix ePO System Tree screenshot showing the System Tree summary and the Group Policy Enforcement Status row highlighted in red

Microsoft Cryptographic Services status

Microsoft Cryptographic Services, or CryptSvc, is used to verify file signatures. Trellix Endpoint reports the status of this service to ePolicy Orchestrator - On-premises to provide improved visibility into the overall health of an endpoint.

Screenshot of Trellix ePolicy Orchestrator System Tree page showing summary, properties, and product information. The Microsoft Cryptographic Services Status row is highlighted and shows the status as Running.

Security posture

When you open the General Policy, you see the Security Posture slider bar. It abstracts the security settings from users who do not want to see the full list, and instead provides a high-level view of the General Policy configuration. Users can choose Balanced, High Protection, and Custom settings to decide the level of detail they want to view for a more personalized user experience.

Trellix Policy Catalog user interface showing the header, Security Posture slider, Exploit Guard Settings, and Real-Time Protection Settings panels

If the slider is moved to one of the predefined states (Balanced or High Protection), the following configuration information remains unchanged:

  • Antivirus management

  • Firewall management

  • Automatic updates delay

  • Uninstall password

  • Signature update sources

Enabling Threat Protection and Firewall management

By default, Threat Protection is enabled when you install Trellix Endpoint. We recommend that you do not disable this feature as advanced malware detection is not operational.

To manage Microsoft Windows Defender Firewall rules, navigate to the ePO - On-prem Policy Catalog and select Trellix Endpoint Management > General. Select a policy and click Firewall.

Note

When Firewall is disabled in the policy, Protection Workspace reports the firewall status as being compliant.

Sending Exploit Guard events to ePO - On-prem - On-prem and ePO - SaaS

Exploit Guard events for Controlled Folder Access and Attack Surface Reduction rules can be reported to Trellix ePolicy Orchestrator - On-premises and Trellix ePolicy Orchestrator - SaaS. Enable this feature by navigating to Policy Catalog and selecting the Send endpoint events to Trellix ePO checkbox under Exploit Guard settings. Event information is viewable in the Threat Event Log. Also, predefined queries templates can be used to report the exploit information. The templates can be found under Queries and Reports > Trellix Groups > Trellix Endpoint.

Screenshot of Trellix Policy Catalog showing Security Posture slider and Exploit Guard Settings. The Send endpoint events to Trellix ePO checkbox is visible and highlighted with a red outline in the screenshot.


General policies

The default policies allow you to configure the general settings for Trellix Endpoint. These include Threat Protection, Firewall, Log Settings, and Compliance Reporting.

There are two templates for the General policy. The first is for general use, and the second is for configurations that require a higher security level. The options are the same for both, but more restrictive settings are used for higher security.

For ePO - On-prem policies, you can duplicate and customize the settings in these default policies, using the standard ePO - On-prem policies workflow. See the documentation for your version of ePO - On-prem on https://docs.trellix.com.

Threat Protection

Threat Protection — Standard options

Option

Definition

Protection level

Use the sliders to set the confidence level when Trellix takes the Block or Report actions for potential malware.

Note:

The lower the confidence level, the stricter the policy, but the higher the chance of generating false-positive results.

Scan Settings

Define the scan type, scanning schedule, and required actions for threats of differing severity for Windows Defender Antivirus. Enable Credential Theft Protection to prevent processes from reading lsass.exe memory (lsass.exe stores user credentials).

Update Scheduler

Set the Update Scheduler options.

  • Check for Trellix Endpoint updates and Microsoft Windows Defender Antivirus definitions after your chosen number of hours.

  • Check for Trellix Endpoint updates and Windows Defender Antivirus definitions at your chosen time on a recurring basis (every day, or on a specific day each week).

  • Check for Windows Defender Antivirus definitions only.

  • Delay product updates

Notifications

As administrator, you can decide if your users see notifications when Trellix Endpoint or Windows Defender Antivirus detects threats on the endpoint devices.

Threat Protection — Advanced options

Option

Definition

Signature update sources distributed from

Windows Defender Antivirus can use several methods to check for and download signature updates. Select the methods to use, and drag and drop them in your preferred order. When using Configuration Manager (SCCM) as the update source, set a time period after which, if SCCM finds no new signature updates, the system falls back to using other update sources.

To check for signature updates from UNC file shares, enter the relevant UNC paths.

Exploit Guard Settings

Manage access to selected folders. Choose Disabled, Block, or Audit from the drop-down list. The lists of controlled folders are defined in the Exclusions policy.

Select the Send endpoint events to Trellix ePO checkbox to report Exploit Guard event information for Controlled Folder Access, Attack Surface Reduction Rules, and Network Protection to ePO - On-prem On-prem and ePO - SaaS.

Note:

Exploit Guard is not supported on Windows Server 2016.

Real-Time Protection Settings

Select the real-time protection configuration to be applied to Windows Defender Antivirus and Trellix Endpoint.

This area includes the ability to enable scanning for potentially unwanted applications (PUA), and to set the action — Block, or Audit Only — when these types of applications are detected.

What to Scan

Select the items that Windows Defender Antivirus and Trellix Endpoint scan.

Additional Scan Settings

Select the settings appropriate for your requirements.

Proxy Server Settings

Configure the proxy server for Trellix Endpoint and Windows Defender to allow you to route threat intelligence from your network to Trellix Endpoint.

Firewall

Firewall — Standard options

Option

Definition

Basic

Choose the profiles that you enable the Firewall management for Decide if the users of each profile see notifications about firewall events..


Firewall — Advanced options

Option

Definition

Advanced

To use existing local firewall rules, select the profiles to which these rules apply.

Note

If you use the Trellix Endpoint Firewall management, and later disable it, the local firewall rules on your managed endpoints are automatically reactivated.

Log Settings

Option

Definition

Log Settings across Trellix Endpoint

Select the information to be included in the log files. (Advanced option) Set the Log Size Limit, and the Log Level. The default settings are suitable for most customers. You can change them if you have specific requirements. For example, if you are troubleshooting an issue, select a more detailed Log Level and increase the Log Size Limit. These log settings provide more detailed information to help diagnose the issue.

Compliance Reporting Settings

Option

Definition

BitLocker Settings

Check the box to enable BitLocker compliance reporting (if enabled, Bitlocker must be installed and running).

Manage automatic updates

Use group policies to automatically update your systems with the latest software. The update scheduler allows you to schedule automatic updates on a timed delay so that you can control when different parts of your organization receive each update.

Make a plan to organize your systems into groups and determine a schedule for rolling out automatic updates to different parts of your organization.

  1. Select Systems → Systems Tree.        

    Categorize the systems in your organization into groups and assign separate policies to each group.

  2. Under System Tree, select a group.

  3. Select the Assigned Policies tab, highlight the General category, and click Edit Assignment.        

    The Policy Assignment window opens.

  4. Under Assigned policy, select Balanced and click New Policy.        

    The Create a new policy window opens.

  5. Complete the options for a new policy.        

    • Category: General

    • Create a policy based on this existing policy: select Balanced

    • Policy Name: Enter a policy name. For example, Sales.

    • Click OK.

    The Trellix Endpoint 22xx: Trellix Endpoint Management → General → Sales window opens.

  6. Under Threat Protection, complete the options for the Update Scheduler.

  • Select the Check for updates every 8 hour(s) option. You can modify the number hours if needed.

  • Select the Delay products updates by (days) checkbox.

  • Enter the number of days.

  • Click Save.

The system returns you to the Policy Assignment window.

7. Click Save to save the policy changes.

The policy is now scheduled to automatically update your systems in your group based on your selections. Create policies for the remaining groups as before.

To make sure that you have scheduled the updates, you can:

  • Use the Trellix Agent Monitor to see whether the service is running.

  • Use the Policy → Policy Comparison page to view and compare the scheduling for different policies.

Prevent users from changing exclusions in Windows Defender

Use policy settings to disable antivirus scan exclusions and improve security on your managed systems.

A user can exclude files, folders, and processes from antivirus scans in Windows Defender using the Exclusions page under Virus and Threat Protection settings. In some instances, you might want to disable this ability. This can be done by enforcing a new policy setting in the Policy Catalog page for the policy.

  1. From your ePO - On-prem interface, browse to Policy Catalog → Trellix Endpoint 22xx → General.

  2. Select a policy and click Edit.

  3. Click Show Advanced. The Additional Scan Settings section is displayed.

  4. Select Disable users from creating scan exclusions.

  5. Click Save.

  6. Make sure you assign the rule to your chosen endpoints. Use Wake Up Agents to push the policies to them.

With the new policy enforced, managed endpoints can no longer add exclusions in Windows Defender. You can verify the change by opening Windows Defender on an endpoint and viewing the exclusions. Note that the Add an exclusion button is disabled and new text reads: Changing exclusions has been disabled by your administrator.

Configure a proxy server for cloud access

Use policy settings to configure a proxy server for Trellix GTI and apply it to your managed systems.

make sure you know the HTTP address and port number of your proxy server.

  1. From your ePO - On-prem interface, browse to Policy Catalog → Trellix Endpoint 22xx → General.

  2. Click Edit.

  3. Click Show Advanced.

  4. Select Configure proxy server. The HTTP address and Port fields appear.

  5. Enter the HTTP address using DNS, IPv4, or IPv6.

  6. Enter the port number.

  7. Click Save.

Note

Click Wake Up Agents to push the policies to your protected endpoints and servers.

Firewall Rules

Trellix Endpoint includes the ability to manage Microsoft Windows Defender Firewall rules on your Microsoft Windows 10 or Microsoft Windows Server 2016 (or later) endpoints and servers.

As with all ePO - On-prem policies, you can duplicate and customize the settings in these default policies, using the standard ePO - On-prem policies workflow. See the documentation for your version of ePO - On-prem on https://docs.trellix.com.

  • Microsoft Windows Defender Firewall, by default, contains two 'top level' rules; one that blocks all inbound connections, and the other, which allows all outbound connections.

  • To have a working system, you must set up rules to allow the inbound connections needed for your normal network connectivity.

  • By default, Trellix Endpoint includes several firewall rules to allow the most commonly used inbound connections.

  • Create further rules to meet your specific needs for inbound connections to your endpoints and servers, and to also create the outbound rules — of both Allow and Block types — to meet your required security objectives.

  • You can sort the default rules by clicking the column heading of any column.

Note

Options in bold contain groups of similar rules.

Option definitions — out-of-the-box inbound allow rules

Rule

Definition

Allow Network Time Protocol traffic

Rule for Network Time Protocol communications.

Allow inbound Remote Desktop Connections (RDP) connections

Inbound RDP connections rule.

App Installer

Rule for the Microsoft App installer, allowing installation and maintenance of Apps.

Connect

Rule for Microsoft PPI Projection.

Core Networking

Rules concerned with allowing networking functions.

Cortana

Rule for Microsoft Cortana communications.

Delivery Optimization

Includes rules for TCP-In and UDP-In.

Mail and Calendar

Rule for Microsoft Windows Communication Apps.

Microsoft Edge

Rule for Microsoft Edge

My Office

Communications with the Microsoft Office hub.

NetBIOS

Includes rules for RCP and NetBIOS sessions.

Network Discovery

Includes multiple rules for network discovery purposes.

OneNote

Rule for Microsoft OneNote communications.

Remote Assistance

Rules for Remote Assistance channels.

Skype

Skype communications rule.

VPN

Rules used to enable VPN communications.

Win32WebViewHost

Rule for Microsoft Windows 32-bit Webview host applications.

Windows AD authentication

Active Directory rules.

Wireless Display

Rules that apply to connections with wireless displays.

Work or school account

Rule for the plug-in to allow work or home account integration.

Your account

Rule for communications with Microsoft Windows cloud account logon.

Add a firewall rule

When defining your firewall policy for your protected endpoints and servers, you can add new firewall rules.

You can create firewall rules that allow communications, or that block communications. These communications can be inbound or outbound, and can apply to programs, services, IP addresses, or to specific protocols or ports. Use the available options to create a rule that meets your specific needs.

Note

This example creates a rule that blocks access from the endpoint to Skype.

  1. From the ePO - On-prem interface, browse to Policy Catalog → Trellix Endpoint 22xx → Firewall Rules.

  2. Click Edit.

  3. Select the group header, or the individual rule in the group for which you want to add a firewall rule.

  4. From the Take action drop-down list, select New Rule. The Details pane is displayed.

  5. Type Block Skype in the rule name text box.

  6. Select the options for the rule:

    • Action: As this example rule is a block rule, select Block.

    • Direction: For this example, select Outbound.

    • Profile: For this example, select the Private and Public profiles.

    • Program: Select Specified path and enter the path to the program, for example C:\Program files (x86)\Microsoft\Skype for Desktop\Skype.exe.

    • Local IP/Remote IP: Set the IP addresses to Any IP address.

    • Protocol and Ports: Set to Any.

    • Advanced: Choose from the following optional settings:

      • Edge Traversal - Choose Block Edge Traversal, Allow Edge Traversal, Defer to User, Defer to Application.

      • Authorized Users Select Any User, Specified User (enter the authorized users or computers)

  7. Click Add.

The new rule to block outgoing connections from the endpoint to Skype is added to the rules in the selected policy.

Note

Make sure you assign the new rule to your selected endpoints, then use Wake Up Agents to push the policies to them.

Edit a firewall rule

When defining your firewall policy for your protected endpoints and servers, you can change existing firewall rules.

  1. From your ePO - On-prem interface, browse to Policy Catalog → Trellix Endpoint 22xx → Firewall Rules.

  2. Click Edit.

  3. Select the rule to change. The Details pane is displayed.

  4. Edit the rule and click Update.

  5. Click Save.

RESULT_CFD01CA6C6B04103B2364E7B829916E2

Blue note icon with pencil" alt="Note icon" style="vertical-align:middle;margin-right:8px;">Note

Make sure you assign the rule to your chosen endpoints, then click Wake Up Agents to push the policies to them.

Delete a firewall rule

When defining your firewall policy for your protected endpoints, remove any rules that you do not want in your policy.

Blue note icon with pencil" alt="Note icon" style="vertical-align:middle;margin-right:8px;">Note

You can't delete rules from the default (read-only) policies.

  1. From your ePO - On-prem interface, browse to Policy Catalog → Trellix Endpoint 22xx → Firewall Rules.

  2. Click Edit.

  3. Select the rule to delete. Use the checkboxes to select multiple rules.

    The Details pane shows the current settings for a rule.

  4. From the Take action drop-down list, select Delete.

Blue note icon with pencil" alt="Note icon" style="vertical-align:middle;margin-right:8px;">Note

When selecting multiple rules, only the rules with checkboxes are affected.

  1. Confirm that you want to delete the selected rules.

  2. Click Save. The selected rule is removed from the policy.

Note

Use Wake Up Agents to push the policies to your protected endpoints.

Copy a firewall rule

When defining your firewall policy for your protected endpoints and servers, you can make copies of existing firewall rules.

  1. From your ePO - On-prem interface, browse to Policy Catalog → Trellix Endpoint 22xx → Firewall Rules.

  2. Click Edit.

  3. The policy opens, showing the existing rules.

  4. Select the rule to copy. Use the checkboxes to select multiple rules.

The Details pane shows the current settings for a rule.

  1. From the Take action drop-down, select Copy. When selecting multiple rules, only the rules with checkboxes are affected.

  2. Confirm that you want to add the copy of the selected rules. When creating multiple copies, you are not prompted until you save.

  3. Click Save. When creating multiple copies, you are warned about the new copies. Click Yes to discard the copies, or No to keep them.

Note

Use Wake Up Agents to push the policies to your protected endpoints.

Exclusions policy

The Exclusions policy contains a single policy template. Duplicate this policy to configure files, folders, and processes to be excluded from the Trellix Endpoint and Windows Defender Antivirus scans.

Option

Excluded by

Definition

Maximum number of characters per field

File and Folder Exclusions

Trellix Endpoint and Windows Defender Antivirus

Enter the folder paths to exclude folders and the files they contain from scheduled and real-time scans.

250

Process Exclusions

Trellix Endpoint and Windows Defender Antivirus

To exclude files opened by processes from being scanned, specify the paths to those processes. All files opened by the specified process are excluded from scans.

100

File Type Exclusions

Windows Defender Antivirus

To prevent scanning of specific file types by scheduled, custom, or real-time scans, add the files types to the File Type Exclusions list.

100

Controlled Folders

Windows Defender Antivirus

Define folders where untrusted applications can't change or delete files or folders. For example, prevent untrusted applications from changing files in the Documents folder.

260

Permitted Applications

Windows Defender Antivirus

Specify the applications to be considered as trusted, and that can change or delete files or folders in the Controlled Folders list.

100

Attack Surface Reduction

Windows Defender Antivirus

Specify the folders or files and resources that should be excluded from Attack Surface Reduction rules.

100

Script Hashes

Trellix Endpoint

Specify SHA256 hashes of scripts to exclude them from real-time scanning.

The number of characters must be 64. Character strings lesser or greater than 64 are not valid.


Note

The exclusions for Controlled Folders and Permitted Applications are applied only if the Honor Protected Folder policy is set to Block or Audit.

Note

There is no limit to the number of exclusion entries you can apply for each policy setting. However, a high number of exclusion entries impacts the length of time it will take to push a policy enforcement down to an endpoint. It is recommended that you add exclusion paths containing multiple executables or applications to reduce the number of individual exclusions to be applied to an individual endpoint.

Wildcards

You can use a single asterisk (*) and question mark (?) as wildcards when defining items in the file name or folder path exclusion list.

Asterisk (*) wildcard

Function

File name and file extension exclusions

Replaces any number of characters. Only applies to files in the last folder defined in a query.

Folder exclusions

Replaces a single folder. Use multiple * with folder slashes \ to indicate multiple, nested folders.

Process exclusions

The asterisk (*) wildcard can only be used at the end of a complete path. For example: C:\MyWork\*.

File name and file extension exclusions

Replaces a single character. Only applies to files in the last folder defined in a query.

Folder exclusions

Replaces a single character in a folder name.

Process exclusions

The question mark (?) wildcard is not supported in process exclusions.

   

Wildcard examples

Wildcard

Expression

Result

Asterisk (*)

C:\MyWork\*.txt

C:\MyWork\notes.txt

C:\someworkpath\*\Data

Any file in:

  • C:\someworkpath\Archives\Data and its subfolders

  • C:\someworkpath\Authorized\Data and its subfolders

C:\Work\*\*\Backup

Any file in:

  • C:\Work\Primary\Denied\Backup and its subfolders

  • C:\Work\Secondary\Allowed\Backup and its subfolders

C:\Work\*\*\Backup (example)

Any matching backup folders under Work paths

Question mark (?)

C:\MyData\my?.zip

C:\MyData\my1.zip

C:\somepath\?\Data

Any file in C:\somepath\P\Data and its subfolders

C:\somepath\test0?\Data

Any file in C:\somepath\test01\Data and its subfolders

C:\somepath\test0?\Data (example)

Any matching files for test0? patterns


Note

Double asterisk (**) is not supported by Trellix Endpoint.

Note

System environmental variables such as %SystemRoot% can be used in exclusions. User environmental variables such as %UserProfile% are not supported by Trellix Endpoint.

Exploit Protection Program Settings policies

Oversee how Trellix Endpoint manages Windows exploit protection. You can export the exploit protection settings from one endpoint, edit your settings, and then push them to all your Trellix Endpoint-managed endpoints and servers.

Option

Definition

Import endpoint exported Settings.xml

Import information about the exploit protection program settings that have previously been exported from a Microsoft Windows system.

Take Action button

Enables you to create a rule, or you can delete or copy a selected rule.

Table grid

Shows all rules from the imported Settings.xml file, and any new or copied rules that have been created. To edit a rule, select it, and make your required changes in the Details pane.

Export Windows exploit protection rules

Export the rules from an existing Windows computer, so that they can then be imported into ePO - On-prem, edited, and then deployed to your endpoints.

  1. From your selected Windows computer, open Windows Defender Security Center.

  2. Open the App & browser control tab.

  3. Locate the Exploit protection area. Click Exploit protection settings.

  4. Click Export settings and choose where to save the settings file.

The Windows Exploit protection settings are saved to a file with the default file name settings.xml.



Import Windows exploit protection settings into ePO - On-prem

Import the exploit protection program settings from Microsoft Windows into ePO - On-prem, so that you can edit the settings and push them to all your Trellix Endpoint-managed systems.

Make sure that you have exported the Windows exploit protection settings from Windows Defender Security Center on a suitable Microsoft Windows computer. Also, make sure you can access the resultant Settings.xml file from where you manage your ePO - On-prem server.

  1. From ePO - On-prem, navigate to Policy Catalog → Trellix Endpoint 22xx → Exploit Protection Program Settings.

  2. Open the selected policy for editing.

  3. Click Choose File, and navigate to your previously saved Settings.xml file. Click Open.

The exploit protection program settings are imported into your selected policy. You can edit the program settings and push the policy to your endpoints.

Verify policy compliance

  1. From the ePO - On-prem interface, navigate to System Tree.

  2. Select the group to which the new policy will be applied.

  3. For each endpoint open system information.

  4. Select the Product tab, and click Trellix Endpoint.

  5. Review the sections compliance information.

  6. If noncompliant devices are present, a Message Center alert is displayed in the top-right corner of the screen.

  7. The Message Center alert provides a link to run a noncompliant device query. This query can also be run by navigating to Reporting > Queries and Reports > Trellix Groups > Trellix Endpoint. The query checks for noncompliant devices and displays device and noncompliant details.


Using Protection Workspace to identify and remediate threats

You can see all potential threats on managed devices and respond to them using Protection Workspace. You can identify threats and navigate seamlessly to any impacted device for remediation.

Protection Workspace helps you answer these questions:

  • What threats are discovered by advanced threat protection technologies from products like Trellix Endpoint and Trellix Endpoint Security (ENS) Adaptive Threat Protection?

  • Why is a device escalated?

  • Where did the threat come from?

  • When was the threat discovered?

Identifying threats and the security status of your devices

The security status of your device is color coded to efficiently prioritize threats and take action.

  • Red — A threat was discovered, or your software or device is running outdated versions and must be updated to be compliant.

  • Yellow — There are threats to investigate or some devices are not up to date.

  • Green — The current state of your environment is healthy, threats have been mitigated, and devices are compliant.

  • Light blue — Information only. No action needed.

  • Gray — No data available.

Using Protection Workspace with Trellix Endpoint

Protection Workspace is a ePO - On-prem component used by several Trellix products.

Protection Workspace is installed by default when using the cloud-based, multi-tenant, ePO - SaaS product. For the on-premises versions of ePO - On-prem (versions 5.3, 5.9, and 5.10), you need to manually install Protection Workspace extensions on your ePO - On-prem server before you can use it.

Because the Protection Workspace is a shared component used by several Trellix products, some of the options and data may vary by product and deployment.

Included might not apply to Trellix Endpoint. As an example, Trellix Endpoint does not use daily DAT updates, it relies instead on Windows Defender Antivirus for the basic definition-based virus detections. So, in the context of Trellix Endpoint, the Protection Workspace → Compliance Overview → Security Content shows the status of your Windows Defender Antivirus installations, but does not list Trellix Endpoint, because this product does not use its own DAT files.

The Protection Workspace provides a visual representation of threat incidents in your environment and device compliance data, all from a single dashboard using several panes. You can quickly identify threats detected in the environment and seamlessly navigate to any impacted device to remediate the threat.

Protection Workspace bar

The Protection Workspace bar displays these details.

Item

Description

Devices

Total number of devices tracked by the ePO - On‑prem server. Systems that have never communicated with ePO - On‑prem are not included in the count.

Escalations

Total number of devices that are tagged as escalated. Select a device to view Escalated Devices. System is escalated if more than 5 threats are detected in 24 hours.

Update

Data on the back-end is automatically refreshed every 60 seconds, and the interface is automatically refreshed every 5 minutes. Click the refresh button to manually redisplay the Protection Workspace with the latest updates.

Settings

Use to adjust the Security Content Color Thresholds and Check‑In Failure Color Thresholds to customize the security levels for your environment.

Threat Overview pane

The Threat Overview pane displays these details.

Item

Description

Escalated Devices

Total number of devices that received a threat over the past 7 days. System is escalated if 5 or more threats are detected in 24 hours.

Resolved Threats

Total number of threats that were resolved in the past 7 days.

Basic — Detected by products like Trellix VirusScan Enterprise, Trellix Endpoint Security (ENS) Threat Prevention, and Microsoft Windows Defender.

Advanced — Detected by products with advanced detection techniques like Trellix Endpoint and Trellix Endpoint Security (ENS) Adaptive Threat Protection.

Unresolved Threats

Total daily count of unresolved threats. Arrow indicates the trend over the past 7 days.

Report Only Detections

Total and daily counts of report-only detections over the past 7 days. Arrow indicates the trend. Select the value to open the details for total or daily threat events.

Encryption Events

Total number of encryption events with critical and major severity over the past 7 days. Arrow indicates the trend. Select the value to open the details for total or daily threat events.

Activity Filters

From the Threat Overview pane, you can drill down to view the device details and the top 5 threats. Select a threat to open the Threat Details pane, and view details about the threat.

Threat Details

The Threat Details pane displays the details of the selected threat.

Item

Description

Threat Details

Displays these basic information about the selected threat event.

  • Name

  • File Name

  • Analyzer Detection Method

  • Reporting Product Name

  • First seen in network

  • Last seen in network

  • Prevalence

  • Age

Advanced Details

Displays the in-depth information about the selected threat event.

  • Agent GUID

  • Event Generated Time

  • Event Category

  • Event ID

  • Threat Severity

  • Threat Type

  • Action Taken

  • Threat Target Host Name

  • Threat Source Process Name

  • Event Description

Affected Devices

Displays the list of devices affected by the selected event.

Story Graph (Trace Summary)

Displays the trace summary for the selected event.

Compliance Overview

The Compliance Overview pane displays these details.

Item

Description

Security Content

Status of the security content in the environment. Here's how the compliance status is calculated for these items:

Trellix Endpoint Security (ENS) AMCore — Number of systems with AMCore content compliant or noncompliant.

  • Compliant — The AMCore content creation date is less than 7 days old.

  • Non-Compliant — The AMCore content creation date is more than 7 days old.

Trellix Endpoint Security (ENS) Exploit Prevention — Number of systems with Exploit Prevention content compliant or noncompliant.

  • Compliant — Enabled state in policy matches the enabled state on client system.

  • Non-Compliant — Enabled state in policy doesn't match the enabled state on client system.

Trellix DAT — An endpoint is considered compliant if the DAT Date is within 7 days from today. For example, if today is July 19, endpoints with a DAT date of July 13 or later are compliant.

Microsoft Windows Defender — An endpoint is considered compliant if the Anti-Virus Signature Last Updated date is within 7 days from today. For example, if today is July 19, endpoints with a DAT date of July 13 or later are compliant.

For Trellix DAT and Microsoft Windows Defender, the endpoint reports the date, which can be viewed on the Products tab of the System Information page.

Software Status

Status of the individual products deployed in the environment. For example, Trellix Endpoint Security (ENS), Trellix Agent, and Trellix Endpoint. The devices are color-coded to indicate the health of the security status (health) of the device.

Device Management

Check-in Failure indicates the number of devices that haven't checked in to the ePO - On-prem server for more than 15 days.

Managed Devices without Protection indicates the number of devices that don't have these antimalware products installed: Threat Prevention, Trellix Endpoint, or VirusScan Enterprise.

Managed Devices indicates the total number of managed devices over the past 7 days.

View the number of devices that have communicated with ePO - On-prem at least once. Systems that have never communicated with ePO - On-prem are not included in the count.

Important

The systems that never communicated with ePO - On-prem appear in the System Tree and not in the Protection Workspace

Devices

The information that appears in the Devices pane changes depending on the category you select:

  • Devices

  • Escalations (default view)

You can view your devices by tags, by System Tree view, or as a list. Use the search feature to quickly find a device.

Important

The systems that never communicated with ePO - On-prem appear in the System Tree and not in Protection Workspace.

Device Details

From the Devices pane, you can drill down to view the device details and the top 5 threats. Select a threat under Recent Threat Events to open the Threat Details pane, and view details about a specific threat.

Threat Event workflow

Protection Workspace provides a snapshot of your network's security status, allowing you to view key threats so you can investigate and determine a response.

  1. Protection Workspace displays key threat events and device compliance across Trellix products.

  2. The security administrator quickly urgent events and escalated devices.

  3. The security team investigates the escalated devices to determine a response.

Illustration showing the Story Graph workflow — three numbered steps (1, 2, 3) with device and analyst icons connected by arrows

View threat events using the Story Graph

The Story Graph allows you to trace the history of threat events using a graphical interface. You can view the story graph in both the Threat Event Log and in Protection Workspace.

Make sure to install the required extensions.

  • Select Reporting > Threat Event Log.

Screenshot of the Trellix Threat Event Log and Story Graph interface showing event details panel on the right

Story Graph is integrated into the Threat Event Log.


  • Click a threat event.

  • View the process trace for the threat event.

Apply Protection Workspace tags to systems

Tag devices (systems) to escalate or exclude them from a compliance check.

  1. In the Protection Workspace, select a device from the tag, tree, or list view.

    The Device Details pane opens.

  2. From the Security State drop-down list, select a tag.

  3. Click Confirm.

Screenshot of the Device Details pane showing device information such as IP address, MAC Address, Operating System, OS Version, Last User, tag badges (e.g., Workstation, Escalated) and the Security State drop-down menu with options including Exclude from Compliance Overview and Remove from Escalations.

Use predefined queries to create reports

Predefined configurable query templates can be used to provide information about exploit events and device compliance. For more information, see Introduction to queries.

  1. From the ePO - On-prem interface, navigate to Reporting > Queries and Reports > Trellix Groups > Trellix Endpoint.

  2. Select the query you want to use from the list and click Run. Reports can be created for information about compliance and exploit events.

Screenshot of the Trellix ePO Queries & Reports interface. The image shows the top application header with menu items (Protection Workspace, Dashboards, System Tree, Queries & Reports, Policy Catalog, Security Resources), a left navigation pane listing Groups including Trellix Groups and Trellix Endpoint highlighted, and the main content area with a Queries & Reports title, New Query / Import Queries buttons, a Quick find search box, and a table of predefined queries (rows with query titles such as Trellix Endpoint Non-Compliant Systems and action links like Details | Run | Dupl). The UI uses grey headers and pale blue row highlights.

  1. To configure a query, select Duplicate to edit and configure as needed.



View Microsoft Windows Defender status

Verify that Microsoft Windows Defender is installed and enabled on your endpoints.

The status of Microsoft Windows Defender on your endpoints is reported during new installations and version upgrades of Trellix Endpoint. Users are notified if Microsoft Windows Defender is either not installed, or installed but not enabled on an endpoint.

  1. Go to System Tree and under Products tab, select Trellix Endpoint.

  2. The Microsoft Windows Defender status on your endpoints is displayed as follows:

Screenshot of the Microsoft Windows Defender status table showing multiple rows and columns — sections titled General and Microsoft Windows Defender with fields such as BitLocker Compliance Reporting, Group Policy Enforcement Status, Language, Microsoft Cryptographic Services Status, Version, Anti-Spyware Signature Age, Anti-Spyware Signature Last Updated, Anti-virus Signature Age, Anti-virus Signature Last Updated, Engine Version, Network Inspection System Signature Age, and corresponding values.

Manage quarantined content

    You can manage quarantined content from the ePO - On-prem System Tree. The Quarantined Content tab, found in the System Tree for each of your configured systems, provides information about content that has been quarantined by compatible products.

    Use the Quarantined Content tab to view information about the files that have been quarantined. You can also release files from quarantine, restoring them, and any related registry entries, to their previous locations on the system where they were quarantined.

        ⚠️ Caution    

Quarantined files have the potential to be malicious. Only restore quarantined content that you know to be safe.

Using the quarantined content area

    The Quarantined Content area for each managed system displays information about the quarantined items from that system.



Name

Description

Detection Name

The name Trellix has given to the item that has been detected and quarantined by Windows Defender Antivirus or Trellix Endpoint. Use Search the Threat Library (https://www.trellix.com/en-us/threat-center.html) to learn more about the detected item.            

Type

The type of item quarantined. Options include:                

  • File

  • Registry entries — Information shows if the detection is a 32-bit or 64-bit registry entry, or if it is a registry value or registry key.

Note:                        

                            For detections made by Windows Defender Antivirus, the quarantined content page displays the information returned from Windows Defender Antivirus. Microsoft defines the information that is displayed, and it might change as Windows Defender Antivirus is updated.  

Quarantined Item

Path and name for the item that has been quarantined.

Hash

If available, the hash value for the quarantined content.

Click the hash value to look up the description of the threat on the VirusTotal information page.                    

Detection Method

How the quarantined item was detected. Options depend on the software using the Quarantine management:

  • Trellix Endpoint

  • Windows Defender Antivirus

Event

Possible Event options are:

  • Section Execution — The detection and quarantine occurred at the point the file was being memory mapped.

  • Process Creation — The detection and quarantine occurred after the process was loaded into memory, and the point of process execution.

  • Download - The detection and quarantine occurred either during the download before the file was saved on disk, or before the extraction of a zip file.

Quarantined Time

The time and data stamp for the quarantine event.

Action (displayed above the table)

Select the quarantined items to be handled, and select the required Action.                

  • Delete — Remove the selected content from quarantine.

  • Restore — Restore the selected content to the endpoint and location where it was quarantined.


Viewing and handling quarantined content

Use the ePO - On-prem System Tree to view information about quarantined content and to take the appropriate actions on that content.

Note

You can configure your policy to automatically delete quarantined content after a specified number of days.

  1. Identify the endpoint with quarantined content. From Protection Workspace, expand Resolved Threats, and look for endpoints and servers that have the Action Taken set to moved.

  2. Log on to ePO - On-prem.

  3. In the System Tree, select the endpoint with the quarantined content.

  4. Click the Quarantined Content tab.        

    Information about the quarantined content for the selected endpoints or servers is displayed.

Screenshot of the ePO Quarantined Content tab showing a table of quarantined items (columns include Detection Name, Type, Quarantined Item, Hash, Detection Method, Event, Quarantined Time) and the 'Take Action' dropdown open with options including Delete and Restore.



  1. Select the quarantined items to be handled, and select the required Action.

    • Delete — Remove the selected content from quarantine.

    • Restore — Restore the selected content to the endpoint and location where it was quarantined.