The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure Trellix APD

Prev Next

To build attack maps, complete the initial portal configuration. Collect asset telemetry and connect your vulnerability scanner API.

Collect endpoint telemetry using the Trellix APD agent

Prerequisites: Configure your firewall to permit outbound access to the Trellix APD tenant.

Ensure the following rules are active:

  • NDR to trellix-apd.com on TCP Port 443.

  • NDR to trellix-apd.com on TCP Port 44305.

  • Endpoints to trellix-apd.com on TCP Port 44305.

Note

You must deploy the Trellix APD agent even if a vulnerability scanner is integrated. The agent discovers vital host and network telemetry needed to calculate risk. The platform cannot scan IP ranges or network segments.

The Trellix APD agent collects the following endpoint data:

  • Hostname and identifying information

  • Operating system version

  • Local users, groups, and group membership

  • User login history

  • Running processes

  • Network interface configuration

  • Listening ports

  • Authorized public SSH keys and PEM-derived keys

  • RDP client usage history

  • Commonly used desktop applications

  • Windows domain controllers, users, and groups

  1. Log in to the Trellix APD portal.

  2. Select the Scanning tab.

  3. Download the script for your operating system.

    • The Windows script is named deepsurface-windows-ephemeral.ps1

    • The Linux script is named deepsurface-linux-ephemeral.sh

    • The macOS script is named deepsurface-macos-ephemeral.sh

  4. Open your command-line interface with administrator privileges on the endpoint.

  5. Bypass the execution policy if the system blocks the script.

  6. Run the script.

Note

The script automatically downloads the lightweight agent. The micro-agent requires 30MB RAM and 2 to 10MB of daily network bandwidth. The local scan typically completes in 2 to 5 minutes. The scanning status displays as “not applicable” until data processing is complete. The script is designed to run dormant on a schedule. Schedule scans weekly, daily, or hourly to minimize performance impact. Best practice involves using a remote endpoint management tool to schedule these scans. Data processing in the cloud requires 8 to 10 hours. View the processed intelligence in the Risk Insights tab.

Deploy the Trellix APD agent using Trellix ePolicy Orchestrator SaaS (ePO - SaaS)

If you are in North America, you can deploy the agent through Trellix ePO - SaaS.

  1. Check the Trellix APD agent into the Trellix ePO SaaS repository.

  2. Deploy the Trellix APD agent globally using the Trellix Agent.

Trellix ePO collects scan data from all endpoints in a staging area. It batches the data update to the APD cloud.

Note

Integration and deployment using ePO - On-prem is not available at this time.

Manual testing workflow

Follow these steps to manually start the job for testing purposes.

  1. Go to the Activity → Tasks page on the Trellix APD portal.

  2. Click Process in the Process Scan Queue.

  3. Enable the checkbox to run the next task in sequence when finished.

    The system manually processes the inputs and imports the vulnerability data and risk analysis.

  4. View the updated information on the Risk Insights page after all jobs complete.

Import vulnerability data from Tenable Security Center

Note

Tenable Security Center must use a publicly accessible IP address to synchronize with the cloud tenant. The portal retains imported vulnerability data for 30 days. You must re-import scans periodically.

  1. Log in to the Trellix APD portal.

  2. Select Settings.

  3. Select Vulnerability Sources.

  4. Select your Tenable environment. Options include Tenable.io, Tenable SaaS, or SecurityCenter Tenable.sc API.

  5. Type the public hostname, administrative username, and password.

  6. Select Save and Test Integration to verify communication with the tenant.

  7. Select Import to pull scan results into the portal.