Exploit Guard Protection is supported for host endpoints running in specific Windows environments only, including Windows XP, Vista, 7, 8, 8.1 or 10. Exploit Guard Protection is not supported for host endpoints running macOS or Linux operating systems. See "Operating System Requirements" in the Endpoint Security (HX) Server Deployment Guide for more information about Trellix Endpoint Security (HX) xAgent versions that support specific Windows, macOS, and Linux operating system versions.
This section covers the following topics:
Exploit Guard Protection for Windows Servers
Exploit Guard Protection also supports Windows server operating systems 2008, 2012, and 2016. By default, Exploit Guard support for Windows servers is disabled, even if the Exploit Guard policy is enabled for other host endpoints. Exploit Guard automatically determines whether a host endpoint is a server and disables Exploit Guard for those endpoints.
In release 4.5 or later, you can enable and disable Exploit Guard processing for server operating systems using the Trellix Endpoint Security (HX) Web UI or API. See Enabling and Disabling Exploit Guard for more information. You cannot enable it with the CLI.
Exploit Guard Processing
Exploit Guard uses a rules file and a whitelist file during its processing. These files are supplied and maintained by Trellix only. The latest files can be downloaded from Trellix's Dynamic Threat Intelligence (DTI) network.
You may encounter some false positive alerts during Exploit Guard Protection processing. If this happens, contact your Trellix Technical Support representative for assistance.
Exploit Guard Global Default Policy Settings
By default, Exploit Guard Protection is enabled for the Agent Default Policy, unless you disabled it. When Exploit Guard Protection is enabled, its exploit detection function is enabled by default but its exploit prevention function is disabled. Both functions can be enabled and disabled completely for all endpoints in your network or by host set. If Exploit Guard Protection is disabled for a policy, it is turned off for all host endpoints assigned to that policy.
Important
Exploit Guard Protection is enabled by default after upgrading or installing Endpoint Security (HX) xAgent software.
Using Exploit Guard Protection policy settings
The Exploit Guard Protection policies you establish for your endpoints determine how Exploit Guard Protection is applied to your endpoints. You can manage Exploit Guard processing through the xAgent default policy and custom policies. For example, when you enable both exploit prevention and exploit detection in the xAgent default policy, exploit prevention can prevent the exploit payload from running, terminate the exploited application, and notify you that an exploit has been blocked on all your host endpoints. See Reviewing Exploit Guard Protection Policies to review settings for your current policies.
Important
Exploit Guard Protection prevention options are only supported on host endpoints running Endpoint Security (HX) xAgent version 22 or later.
Data loss may occur when exploit prevention blocks an exploit payload from executing and terminates the process that started the infection. For example, Microsoft Word runs a single process instance for all open documents. If you have multiple documents open in Microsoft Word, and an exploit is blocked for one of them, exploit prevention terminates the Microsoft Word process instance. This terminates all of your open documents, which may result in data loss.
Important
Trellix recommends that you disable the Terminate the Exploited Process option for xAgent default policy. Data loss may occur when an exploited process is terminated.
If you do not want Exploit Guard Protection enabled on specific Windows endpoints or servers, create an Exploit Guard Protection custom policy in the Web UI to exclude these endpoints from Exploit Guard Protection processing. See "Operating System Requirements" in the Endpoint Security Agent (HX) Deployment Guide to determine Windows operating system versions and Windows server operating system versions supported by Endpoint Security (HX) xAgent software version 35.
The following table summarizes the Exploit Guard Protection policy settings.
Policy Setting | Description | Link |
|---|---|---|
Enable and disable Exploit Guard Protection | Enable and disable both exploit detection and exploit prevention for all host sets assigned to a specific policy. When this option is disabled, no Exploit Guard processing occurs for endpoints in the assigned host sets. | |
Configure the global Exploit Guard policy (Use the xAgent default policy). | Enable and disable exploit prevention for all host endpoints. | |
Specify exploit prevention options. | ||
Exclude specific monitored applications from Exploit Guard Protection (exploit detection and prevention) processing for all hosts in your enterprise. | See Excluding Monitored Applications from Exploit Guard Processing. | |
Exclude or whitelist specific files and folders from Exploit Guard Protection (exploit detection and prevention) processing for all host endpoints in your enterprise. Excluded files and folders are added to the whitelist file. | See Excluding Files and Folders from Exploit Guard Processing. | |
Exclude or whitelist specific MD5 hashes from Exploit Guard Protection (exploit detection and prevention) processing for all hosts in your enterprise. Excluded MD5 hashes are added to the whitelist file. | ||
Maintain the exception policy. NoteUsing an exception policy is not recommended. | Select host sets for the exception policy. | |
Identify specific monitored applications that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy. | See Using an Exception Policy to Exclude Monitored Applications. | |
Identify specific files and folders that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy. | ||
Identify specific MD5 hashes that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy. |
Monitored application versions
The following table lists the versions of the applications monitored by the Trellix Endpoint Security (HX) xAgent during Exploit Guard Protection processing.
Application | Application Version | xAgent Versions | |||||||
|---|---|---|---|---|---|---|---|---|---|
22.41 | 23.10 | 24.9 | 25.12 | 26.21 | 27.30 | 28.8 | 35.31.0 | ||
Adobe Reader | 9.0 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
10.0 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
11.0 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
DC | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
Adobe Flash | 10.0 (and later) | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Internet Explorer | 8.0 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
9.0 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
10.0 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
11.0 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
FireFox | 25.0 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Latest | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
Google Chrome | Latest | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Java | 7.0.100 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Microsoft Office (Word, Excel, PowerPoint) | 2007 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
2010 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
2013 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
2016 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
365 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | |
Microsoft Outlook | 2007 | No | No | No | Yes | Yes | Yes | Yes | Yes |
2010 | No | No | No | Yes | Yes | Yes | Yes | Yes | |
2013 | No | No | No | Yes | Yes | Yes | Yes | Yes | |
2016 | No | No | No | Yes | Yes | Yes | Yes | Yes | |
365 | No | No | No | Yes | Yes | Yes | Yes | Yes | |
Exploit Guard is not supported on endpoints where the monitored applications are streamed from a virtual application server, such as App-V, Xenapp, or VMware ThinApp. Streamed applications should be excluded from Exploit Guard processing for the affected endpoints. If all your endpoints are affected, use a global policy; if only a few endpoints are affected, use host sets in an exception policy.
See Excluding Monitored Applications from Exploit Guard Processing or Defining Exploit Guard Protection Exclusion Policies.
Exploit Guard Protection notifications
Notifications are enabled by default when exploit prevention is enabled in the xAgent default policy or a custom policy. You will receive a confirmation message when an exploit is blocked. User notifications in Windows environments are translated into Chinese (simplified and traditional), French, German, Italian, Japanese, Korean, Portuguese Brazilian, Russian, and Spanish.
Note
Internationalization for exploit prevention notifications is supported for Windows endpoints running Endpoint Security (HX) xAgent version or later.
The language translation will match your Windows UI language selection. For example, if the language selection for your Windows explorer.exe is Chinese, your exploit prevention notifications are translated into Chinese. If your Windows UI language selection does not match one of the supported languages, you will receive exploit prevention notifications in English.
Note
English is the default language for Exploit Guard Protection prevention notifications.