Self Protection protects the security software files from threats. One of the first things that malware attempts to do during an attack is to change, delete, or disable your system security software. Configure the Self Protection settings to protect Endpoint Security for Linux files and its module files from being changed or deleted.
Trellix ENS for Linux supports only the Files and Folders option in Self Protection.
You achieve these when you enable self protection:
Files and folder located in
/opt/McAfee/ens/ and /var/McAfee/ens/will be protected.Create, write, delete, hardlink, softlink, rename, change permissions, and change owner operations will be permitted only by Trellix processes; no other processes can perform these permissions.
Perform these steps to enable Self Protection:
Log on to the ePO - On-prem server as an administrator.
From the Policy Catalog, select Endpoint Security Common as the product, then Options as the category.
Click Edit Policy.
On the Policy Catalog page, click Show Advanced.
In Self Protection, select Enable Self Protection and Files and Folders.
Note
For managed systems, deselecting Enable Self Protection or Files and folders disables Self Protection. We recommend that you enable self protection always because malware attacks primarily target the software files first.
Select one of these Actions:
Block and Report — Blocks users from changing or deleting the software files and writes the details of violation in the product logs.
Block only — Prevents users from changing or deleting the software files.
Report only — Records the violation details in the product logs when a linux user deletes or changes the software files.
Click Save.