Trellix Secure Policy in Policy Catalog under Application Control Rules (Windows) and Configuration (client) are added to make sure only required policies are applied to the endpoints for secure/restricted product functionality.
This includes predefined rules having limited updaters and skips lists in it to make sure the system is more secure. This Policy is not the default policy. This policy prioritizes security over usability. Lot of rules that allow applications to run have been removed, and this might cause failures in third-party applications, this policy must be tested thoroughly before deploying to production environments.
Trellix Secure Policy Under Application Control Rules (Windows) contains these rules from Trellix Default Rules
Default List
Execution Control Rules
Internet Printing
Local User
Trellix
Trellix DLP Agent
Trellix Exclusion Filters
Trellix Group Shields
Trellix Publisher
SCCM/SMS ClientRestricted - (
CcmExec.exe, SMSCliUI.exe, ScanWrapper.exe, CcmSetup.exe, windowsupdatebox.exe. Only these updaters are added as secure)System Information
Terminal Server
USB Plug and Play
Windows AD server
Windows Component(secure) -
sysocmgr.exe, cleanmgr.exe, shrpubw.exe, wmiadap.exe, compmgmtlauncher.exe, ServerManagerLauncher.exe, SMSS.exeWindows Defender
Windows Metro App
Windows Secure - Windows rule group has been changed. Add Windows Secure by making only
system32\Wsqmcons.exeas an updater.Windows Server Update 2.0 sp1
Windows Update(Secure) -
GWXConfigManager.exe, System32\LogonUI.exe, svchost.exewith library assystem32\wups.dll, andsvchost.exewith library assystem32\wups2.dll, TiWorker.exe, wusa.exe, searchUI.exe, onedrivestandaloneupdater.exe, msdt.exe, iexplore.exeare removed from the updaters list.
Trellix Secure Policy Under Configuration (Client) contains PathsWritableOnlyByUpdater config. This configuration changes can't be made from policy. If you apply this configuration, policy client gets updated with below paths and these paths will be write protected after system reboot:
c:\windows\ccmsetup;c:\windows\ccmcache;c:\windows\system32\ccm\setup;c:\windows\system32\ccm\cache;c:\windows\syswow64\ccm\setup;c:\windows\syswow64\ccm\cache
c:\windows\ccmsetup;c:\windows\ccmcache;c:\windows\system32\ccm\setup;c:\windows\system32\ccm\cache;c:\windows\syswow64\ccm\setup;c:\windows\syswow64\ccm\cache;c:\windows\ccm\systemtemp
Note
Only updater processes are allowed to change these write protected path. This setting overrides trusted volume rules.