The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

What to do first

Prev Next

Once installed, Threat Prevention uses the content files packaged with the product to provide general security for your environment. We recommend that you download the latest content files and customize the configuration to meet your requirements before deploying to client systems.

Immediately after installation:

Note

Exploit Prevention is not supported in the ARM architecture.

  1. Set user interface security — Configure the access options and password to control access to specific components or the whole Trellix Endpoint Security (ENS) Client interface.

  2. Configure logging on the client — Specify the location of log files for Endpoint Security features, types of information, and severity level of events to log. Select which client events to forward to Trellix ePO - On-prem and whether to log events to the Windows Application log.

  3. Confirm engine and content filesVerify that client systems have the latest engine and content files installed using Trellix Endpoint Security (ENS) Client or Trellix ePO - On-prem. Verify that client systems have the latest engine and content files installed using Trellix Endpoint Security (ENS) Client.

  4. Prevent intrusions — Make sure Access Protection and Exploit Prevention are enabled, specify reactions to signatures and exclusions, and configure rules to prevent unwanted changes to commonly used files and settings.

  5. Configure settings that apply to all scans:

    • Quarantine location and the number of days to keep quarantined items before automatically deleting them

    • Detection names to exclude from scans

    • Potentially unwanted programs such as spyware and adware to detect

  6. Configure scans that run automatically when files are accessed — Configure the on-access scanner to detect and respond to potential threats as files are accessed in your environment. Enable detection of potentially unwanted programs.

  7. Configure and schedule regular targeted scans — Configure on-demand scans to perform:

    • Daily memory scans

    • Weekly or daily scans of active user locations, such as user profile folder, Temp folder, registry entries, registered files, and Windows folder

  8. Configure engine and content file updates — Configure a Trellix Agent Product Update client task to make sure that you have the most current content files, engine, and product upgrades.