To verify that Enable Self Protection on a standalone Mac is active and functioning as expected, you can attempt to manually stop a Trellix ENS for Mac service using the command. Self Protection is functioning correctly if the operation is denied, preventing the service from stopping. The protected Trellix files and processes cannot be modified or stopped while Self Protection is enabled.
Open a Terminal window.
Run a command to stop a Trellix ENSM service:
sudo /usr/local/McAfee/fmp/bin/fmp stop
The operation is blocked and the command fails with an "Operation not permitted" error, indicating that Self Protection is functioning as expected.