Once installed, Threat Prevention uses the content files packaged with the product to provide general security for your environment. We recommend that you download the latest content files and customize the configuration to meet your requirements before deploying to client systems.
Immediately after installation:
Note
Exploit Prevention is not supported in the ARM architecture.
Set user interface security — Configure the access options and password to control access to specific components or the whole Trellix Endpoint Security (ENS) Client interface.
Configure logging on the client — Specify the location of log files for Endpoint Security features, types of information, and severity level of events to log. Select which client events to forward to Trellix ePO - On-prem and whether to log events to the Windows Application log.
Confirm engine and content files — Verify that client systems have the latest engine and content files installed using Trellix Endpoint Security (ENS) Client or Trellix ePO - On-prem. Verify that client systems have the latest engine and content files installed using Trellix Endpoint Security (ENS) Client.
Prevent intrusions — Make sure Access Protection and Exploit Prevention are enabled, specify reactions to signatures and exclusions, and configure rules to prevent unwanted changes to commonly used files and settings.
Configure settings that apply to all scans:
Quarantine location and the number of days to keep quarantined items before automatically deleting them
Detection names to exclude from scans
Potentially unwanted programs such as spyware and adware to detect
Configure scans that run automatically when files are accessed — Configure the on-access scanner to detect and respond to potential threats as files are accessed in your environment. Enable detection of potentially unwanted programs.
Configure and schedule regular targeted scans — Configure on-demand scans to perform:
Daily memory scans
Weekly or daily scans of active user locations, such as user profile folder, Temp folder, registry entries, registered files, and Windows folder
Configure engine and content file updates — Configure a Trellix Agent Product Update client task to make sure that you have the most current content files, engine, and product upgrades.