Trellix Secure Policy

Prev Next

Trellix Secure Policy in Policy Catalog under Application Control Rules (Windows) and Configuration (client) are added to make sure only required policies are applied to the endpoints for secure/restricted product functionality.

This includes predefined rules having limited updaters and skips lists in it to make sure the system is more secure. This Policy is not the default policy. This policy prioritizes security over usability. Lot of rules that allow applications to run have been removed, and this might cause failures in third-party applications, this policy must be tested thoroughly before deploying to production environments.

Note

Trellix Secure Policy is compatible only with Application and Change Control 8.3.3 and above.

Trellix Secure Policy Under Application Control Rules (Windows) contains these rules from Trellix Default Rules

  • Default List

  • Execution Control Rules

  • Internet Printing

  • Local User

  • Trellix

  • Trellix DLP Agent

  • Trellix Exclusion Filters

  • Trellix Group Shields

  • Trellix Publisher

  • SCCM/SMS ClientRestricted - (CcmExec.exe, SMSCliUI.exe, ScanWrapper.exe, CcmSetup.exe, windowsupdatebox.exe. Only these updaters are added as secure)

  • System Information

  • Terminal Server

  • USB Plug and Play

  • Windows AD server

  • Windows Component(secure) - sysocmgr.exe, cleanmgr.exe, shrpubw.exe, wmiadap.exe, compmgmtlauncher.exe, ServerManagerLauncher.exe, SMSS.exe

  • Windows Defender

  • Windows Metro App

  • Windows Secure - Windows rule group has been changed. Add Windows Secure by making only system32\Wsqmcons.exe as an updater.

  • Windows Server Update 2.0 sp1

  • Windows Update(Secure) - GWXConfigManager.exe, System32\LogonUI.exe, svchost.exe with library as system32\wups.dll, and svchost.exe with library as system32\wups2.dll, TiWorker.exe, wusa.exe, searchUI.exe, onedrivestandaloneupdater.exe, msdt.exe, iexplore.exe are removed from the updaters list.

Trellix Secure Policy Under Configuration (Client) contains PathsWritableOnlyByUpdater config. This configuration changes can't be made from policy. If you apply this configuration, policy client gets updated with below paths and these paths will be write protected after system reboot:

c:\windows\ccmsetup;c:\windows\ccmcache;c:\windows\system32\ccm\setup;c:\windows\system32\ccm\cache;c:\windows\syswow64\ccm\setup;c:\windows\syswow64\ccm\cache

c:\windows\ccmsetup;c:\windows\ccmcache;c:\windows\system32\ccm\setup;c:\windows\system32\ccm\cache;c:\windows\syswow64\ccm\setup;c:\windows\syswow64\ccm\cache;c:\windows\ccm\systemtemp

Note

Only updater processes are allowed to change these write protected path. This setting overrides trusted volume rules.