Configuring the Threat Prevention Policy

The Threat Prevention policy includes these components:

  • Web & Files Protection - Includes download protection, credential protection and Files protection.

  • Behavioral Protection - Includes Anti-Bot, Anti-Ransomware and Anti-Exploit.

  • Analysis & Remediation - Includes forensics and file Remediation.

The Threat Prevention policy unifies all the Threat Prevention components. This is different from the Policy Rule Base in SmartEndpoint, where each Threat Prevention component has its own set of rules. The unified policy lets the administrator control all Threat Prevention components in one Policy. Each rule in the Policy defines the scope which the rule applies to and the Threat Prevention components which are activated.

The Threat Prevention policy contains a pre-defined Default Policy rule, which applies to the entire organization.

Each new rule you create, has pre-defined settings, which you can then edit in the right section of the screen.

The Policy Rule Base consists of these parts:

Policy Rule Definition Reference

Column Description

Rule Number

The sequence of the rules is important because the first rule that matches traffic according to the protected scope is applied.

Rule Name

Give the rule a descriptive name.

Applied to

The protected scope, to which the rule applies.

  • Web & Files Protection

  • Behavioral Protection

  • Analysis & Remediation

The policy components.

Policy toolbar options

The Policy toolbar includes these options:

To do this Click this
Create a new rule
Save, view, or discard changes
Duplicate a rule
Install Policy
Search for entity
Delete a rule