Use default Access Protection rules or create custom rules to protect your system's access points.
Default Trellix-defined rules are always applied before any user-defined rules.
Rule type | Description | You can... | You can't... |
|---|---|---|---|
Trellix-defined rules | These rules prevent change to commonly used files and settings. When the content file is updated, the signatures are updated if needed. |
|
|
User-defined rules | These rules supplement the protection provided by Trellix-defined rules.
|
|
Important
Registry READ operations are very expensive in terms of system resources and performance. These rules should only be used in emergency situations due to the expected performance issues that can occur and are not intended for general use.
Exclusions
At the rule level, exclusions and inclusions apply to the specified rule. Otherwise, exclusions apply to all rules. Exclusions are optional.
Example rule to protect a process
Create an Access Protection rule to prevent the Command Prompt (cmd.exe) from being used to run PowerShell (powershell.exe):
Add the cmd.exe executable to the rule.
Add a subrule and select:
Processes subrule type
Run operation
Add a subrule target executable and specify "powershell.exe" as the file name.