The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Tuning Host Intrusion Prevention

Prev Next

Tuning involves balancing intrusion prevention protection with access to required information and applications per group type. Tuning involves finding the right balance between protecting your environment from intrusions and allowing access to required information and applications.

During Host Intrusion Prevention deployment, identify a few distinct usage profiles and create policies for them. The best way to achieve this goal is to set up a test deployment, then begin reducing the number of false positives and generated events. This process is called tuning.

Automatic tuning using Adaptive mode

Automatic tuning removes the need to constantly monitor all events and activities for all users.

To help tune protection settings, place clients in Adaptive mode. In Adaptive mode, client rules are created automatically to allow legitimate activity. After client rules are created, analyze them and decide which to convert to server-mandated policies.

Often in a large organization, avoiding disruption to business takes priority over security concerns. For example, you might need to install new applications on some computers, and you might not have the time or resources to immediately tune them. You can place specific computers in Adaptive mode to profile a newly installed application, and forward the resulting client rules to the management server. You can then promote these client rules to an existing or new policy and apply the policy to other computers to handle the new software.

Important

Systems in Adaptive mode have virtually no protection. For this reason, use Adaptive mode only for tuning an environment, then turn it off to tighten the system’s protection.

  1. Apply Adaptive mode for Firewall policies.

  2. Review the lists of client rules.

  3. Promote appropriate client rules to administrative policy rules.

  4. After at least a week, turn off Adaptive mode.

  5. Monitor the test group for a few days to make sure that the policy settings are appropriate and offer the wanted protection.

  6. Repeat this process with each group of similar computers.

Manual tuning

Manual tuning requires direct monitoring of events and client rules that are created.

  1. Monitor events for false positives and create exceptions or trusted applications to prevent these events from reoccurring.

  2. Monitor network traffic and define trusted networks to allow appropriate network traffic.

  3. Monitor the effects of the new exceptions, trusted executables, and trusted networks.

  4. If these rules prevent false positives, keep network traffic to a minimum, and allow legitimate activity, add them to the policy.

  5. Apply the new policy to a set of computers and monitor the results.

  6. Repeat this process with each group of similar computers.