Using Exploit Guard Protection policy settings

Prev Next

The Exploit Guard Protection policies you establish for your endpoints determine how Exploit Guard Protection is applied to your endpoints. You can manage Exploit Guard processing through the xAgent default policy and custom policies. For example, when you enable both exploit prevention and exploit detection in the xAgent default policy, exploit prevention can prevent the exploit payload from running, terminate the exploited application, and notify you that an exploit has been blocked on all your host endpoints. See Reviewing Exploit Guard Protection Policies to review settings for your current policies.

Important

Exploit Guard Protection prevention options are only supported on host endpoints running Endpoint Security (HX) xAgent version 22 or later.

Data loss may occur when exploit prevention blocks an exploit payload from executing and terminates the process that started the infection. For example, Microsoft Word runs a single process instance for all open documents. If you have multiple documents open in Microsoft Word, and an exploit is blocked for one of them, exploit prevention terminates the Microsoft Word process instance. This terminates all of your open documents, which may result in data loss.

Important

Trellix recommends that you disable the Terminate the Exploited Process option for xAgent default policy. Data loss may occur when an exploited process is terminated.

If you do not want Exploit Guard Protection enabled on specific Windows endpoints or servers, create an Exploit Guard Protection custom policy in the Web UI to exclude these endpoints from Exploit Guard Protection processing. See "Operating System Requirements" in the Endpoint Security Agent (HX) Deployment Guide to determine Windows operating system versions and Windows server operating system versions supported by Endpoint Security (HX) xAgent software version .

The following table summarizes the Exploit Guard Protection policy settings.

Policy Setting

Description

Link

Enable and disable Exploit Guard Protection

Enable and disable both exploit detection and exploit prevention for all host sets assigned to a specific policy. When this option is disabled, no Exploit Guard processing occurs for endpoints in the assigned host sets.

See Enabling and Disabling Exploit Guard.

Configure the global Exploit Guard policy (Use the xAgent default policy).

Enable and disable exploit prevention for all host endpoints.

See Enabling and Disabling Exploit Prevention.

Specify exploit prevention options.

See Enabling and Disabling Exploit Prevention.

Exclude specific monitored applications from Exploit Guard Protection (exploit detection and prevention) processing for all hosts in your enterprise.

See Excluding Monitored Applications from Exploit Guard Processing.

Exclude or whitelist specific files and folders from Exploit Guard Protection (exploit detection and prevention) processing for all host endpoints in your enterprise. Excluded files and folders are added to the whitelist file.

See Excluding Files and Folders from Exploit Guard Processing.

Exclude or whitelist specific MD5 hashes from Exploit Guard Protection (exploit detection and prevention) processing for all hosts in your enterprise. Excluded MD5 hashes are added to the whitelist file.

See Excluding MD5 Hashes from Exploit Guard Processing.

Maintain the exception policy.

Note

Using an exception policy is not recommended.

Select host sets for the exception policy.

See Adding Host Sets to the Exploit Guard Exception Policy.

Identify specific monitored applications that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy.

See Using an Exception Policy to Exclude Monitored Applications.

Identify specific files and folders that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy.

See Excluding Files and Folders.

Identify specific MD5 hashes that should be excluded from Exploit Guard Protection (exploit detection and prevention) processing for the hosts in the host sets selected for the exception policy.

See Managing Exception Policy MD5 Hash Exclusions.