The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Test Exploit Prevention installation

Prev Next

From the policy, enable Exploit Prevention and update signature 50001 with block and report access. Apply the policy to the client machine.

  1. Run the command to check if Exploit Prevention is enabled or disabled.

    ./mfetpcli --getepstatus

  2. To check the status of signatures, run:

    ./mfetpcli --getallepsignatures

    Note

    Block and report status for signature ID 50001 should be shown as enabled.

  3. Use this command to check violation of the rule:

    touch/usr/bin/watchbog

You will see permission denied as the Block status is enabled. And the event is reported to ePO.