Understanding Exploit Guard Protection

Prev Next

Exploit Guard Protection is supported for host endpoints running in specific Windows environments only, including Windows XP, Vista, 7, 8, 8.1 or 10. Exploit Guard Protection is not supported for host endpoints running macOS or Linux operating systems. See "Operating System Requirements" in the Endpoint Security (HX) Server Deployment Guide for more information about Trellix Endpoint Security (HX) xAgent versions that support specific Windows, macOS, and Linux operating system versions.

This section covers the following topics:

Exploit Guard Protection for Windows Servers

Exploit Guard Protection also supports Windows server operating systems 2008, 2012, and 2016. By default, Exploit Guard support for Windows servers is disabled, even if the Exploit Guard policy is enabled for other host endpoints. Exploit Guard automatically determines whether a host endpoint is a server and disables Exploit Guard for those endpoints.  

In release 4.5 or later, you can enable and disable Exploit Guard processing for server operating systems using the Trellix Endpoint Security (HX) Web UI or API. See Enabling and Disabling Exploit Guard for more information. You cannot enable it with the CLI.

Exploit Guard Processing

Exploit Guard uses a rules file and a whitelist file during its processing. These files are supplied and maintained by Trellix only. The latest files can be downloaded from Trellix's Dynamic Threat Intelligence (DTI) network.

You may encounter some false positive alerts during Exploit Guard Protection processing. If this happens, contact your Trellix Technical Support representative for assistance.Technical Support

Exploit Guard Global Default Policy Settings

By default, Exploit Guard Protection is enabled for the Agent Default Policy, unless you disabled it.  When Exploit Guard Protection is enabled, its exploit detection function is enabled by default but its exploit prevention function is disabled. Both functions can be enabled and disabled completely for all endpoints in your network or by host set. If Exploit Guard Protection is disabled for a policy, it is turned off for all host endpoints assigned to that policy.

Important

Exploit Guard Protection is enabled by default after upgrading or installing Endpoint Security (HX) xAgent software.

Using Exploit Guard Protection policy settings

The Exploit Guard Protection policies you establish for your endpoints determine how Exploit Guard Protection is applied to your endpoints. You can manage Exploit Guard processing through the xAgent default policy and custom policies. For example, when you enable both exploit prevention and exploit detection in the xAgent default policy, exploit prevention can prevent the exploit payload from running, terminate the exploited application, and notify you that an exploit has been blocked on all your host endpoints. See Reviewing Exploit Guard Protection Policies to review settings for your current policies.

Important

Exploit Guard Protection prevention options are only supported on host endpoints running Endpoint Security (HX) xAgent version 22 or later.

Data loss may occur when exploit prevention blocks an exploit payload from executing and terminates the process that started the infection. For example, Microsoft Word runs a single process instance for all open documents. If you have multiple documents open in Microsoft Word, and an exploit is blocked for one of them, exploit prevention terminates the Microsoft Word process instance. This terminates all of your open documents, which may result in data loss.

Important

Trellix recommends that you disable the Terminate the Exploited Process option for xAgent default policy. Data loss may occur when an exploited process is terminated.

If you do not want Exploit Guard Protection enabled on specific Windows endpoints or servers, create an Exploit Guard Protection custom policy in the Web UI to exclude these endpoints from Exploit Guard Protection processing. See "Operating System Requirements" in the Endpoint Security Agent (HX) Deployment Guide to determine Windows operating system versions and Windows server operating system versions supported by Endpoint Security (HX) xAgent software version 35.

The following table summarizes the Exploit Guard Protection policy settings.

Policy Setting

Description

Link

Enable and disable Exploit Guard Protection

Enable and disable both exploit detection and exploit prevention for all host sets assigned to a specific policy. When this option is disabled, no Exploit Guard processing occurs for endpoints in the assigned host sets.

See Enabling and Disabling Exploit Guard.

Configure the global Exploit Guard policy (Use the xAgent default policy).

Enable and disable exploit prevention for all host endpoints.

See Enabling and Disabling Exploit Prevention.

Specify exploit prevention options.

See Enabling and Disabling Exploit Prevention.

Exclude specific monitored applications from Exploit Guard Protection (exploit detection and prevention) processing for all hosts in your enterprise.

See Excluding Monitored Applications from Exploit Guard Processing.

Exclude or whitelist specific files and folders from Exploit Guard Protection (exploit detection and prevention) processing for all host endpoints in your enterprise. Excluded files and folders are added to the whitelist file.

See Excluding Files and Folders from Exploit Guard Processing.

Exclude or whitelist specific MD5 hashes from Exploit Guard Protection (exploit detection and prevention) processing for all hosts in your enterprise. Excluded MD5 hashes are added to the whitelist file.

See Excluding MD5 Hashes from Exploit Guard Processing.

Maintain the exception policy.

Note

Using an exception policy is not recommended.

Select host sets for the exception policy.

See Adding Host Sets to the Exploit Guard Exception Policy.

Identify specific monitored applications that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy.

See Using an Exception Policy to Exclude Monitored Applications.

Identify specific files and folders that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy.

See Excluding Files and Folders.

Identify specific MD5 hashes that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy.

See Managing Exception Policy MD5 Hash Exclusions.

Monitored application versions

The following table lists the versions of the applications monitored by the Trellix Endpoint Security (HX) xAgent during Exploit Guard Protection processing.

Application

Application Version

xAgent Versions

22.41

23.10

24.9

25.12

26.21

27.30

28.8

35.31.0

Adobe Reader

9.0

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

10.0

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

11.0

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

DC

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Adobe Flash

10.0 (and later)

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Internet Explorer

8.0

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

9.0

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

10.0

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

11.0

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

FireFox

25.0

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Latest

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Google Chrome

Latest

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Java

7.0.100

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Microsoft Office

(Word, Excel, PowerPoint)

2007

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

2010

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

2013

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

2016

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

365

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Microsoft Outlook

2007

No

No

No

Yes

Yes

Yes

Yes

Yes

2010

No

No

No

Yes

Yes

Yes

Yes

Yes

2013

No

No

No

Yes

Yes

Yes

Yes

Yes

2016

No

No

No

Yes

Yes

Yes

Yes

Yes

365

No

No

No

Yes

Yes

Yes

Yes

Yes

Exploit Guard is not supported on endpoints where the monitored applications are streamed from a virtual application server, such as App-V, Xenapp, or VMware ThinApp. Streamed applications should be excluded from Exploit Guard processing for the affected endpoints. If all your endpoints are affected, use a global policy; if only a few endpoints are affected, use host sets in an exception policy.

See Excluding Monitored Applications from Exploit Guard Processing or Defining Exploit Guard Protection Exclusion Policies.

Exploit Guard Protection notifications

Notifications are enabled by default when exploit prevention is enabled in the xAgent default policy or a custom policy. You will receive a confirmation message when an exploit is blocked. User notifications in Windows environments are translated into Chinese (simplified and traditional), French, German, Italian, Japanese, Korean, Portuguese Brazilian, Russian, and Spanish.

Note

Internationalization for exploit prevention notifications is supported for Windows endpoints running Endpoint Security (HX) xAgent version or later.

The language translation will match your Windows UI language selection. For example, if the language selection for your Windows explorer.exe is Chinese, your exploit prevention notifications are translated into Chinese. If your Windows UI language selection does not match one of the supported languages, you will receive exploit prevention notifications in English.

Note

English is the default language for Exploit Guard Protection prevention notifications.