@@ -358,6 +358,27 @@ def LsarLookupNames(self, dce, policyHandle, service):
358358 {"name" : "sophoslivequery_*" , "processes" : ["" ]}
359359 ]
360360 },
361+ {
362+ "name" : "Trellix Endpoint Detection and Response (EDR)" ,
363+ "services" : [
364+ {"name" : "McAfee Endpoint Security Platform Service" , "description" : "Trellix Core Service" },
365+ {"name" : "mfemactl" , "description" : "Trellix Management Service" },
366+ {"name" : "mfemms" , "description" : "McAfee Management Service" },
367+ {"name" : "mfefire" , "description" : "Trellix Firewall Core Service" },
368+ {"name" : "masvc" , "description" : "Trellix Agent Service" },
369+ {"name" : "macmnsvc" , "description" : "Trellix Agent Common Service" },
370+ {"name" : "mfetp" , "description" : "Trellix Endpoint Threat Prevention Service" },
371+ {"name" : "mfewc" , "description" : "Trellix Endpoint Security Web Control Service" },
372+ {"name" : "mfeaack" , "description" : "Trellix Anti-Malware Core Service" }
373+ ],
374+ "pipes" : [
375+ {"name" : "TrellixEDR_Pipe_*" , "processes" : ["McAfeeEDR.exe" ]},
376+ {"name" : "mfemactl_*" , "processes" : ["mfemactl.exe" ]},
377+ {"name" : "mfefire_*" , "processes" : ["mfefire.exe" ]},
378+ {"name" : "McAfeeAgent_Pipe_*" , "processes" : ["McAfeeAgent.exe" ]},
379+ {"name" : "mfetp_*" , "processes" : ["mfetp.exe" ]}
380+ ]
381+ },
361382 {
362383 "name" : "Trend Micro Endpoint Security" ,
363384 "services" : [
0 commit comments