The "Full" version of this security suite includes four core modules that work together to provide multi-layered defense:
This is the primary defense engine that automatically scans files upon access and runs scheduled On-Demand Scans . It includes Antimalware Scan Interface (AMSI) integration to detect malicious non-browser-based scripts.
Includes Scan Cache improvements that utilize "Trust Scan" data to reduce duplicate scanning, significantly lowering CPU impact during full system scans. McAfee Endpoint Security 10.7.0.1390.13 Full
Version 10.7.0 introduced several critical enhancements aimed at performance and visibility:
Monitors and regulates all communication between the computer and the network or internet, blocking suspicious incoming or outgoing traffic. The "Full" version of this security suite includes
Includes features like "Detect unknown ransomware based on behavior" and the creation of bait files (honeypots) to identify and block ransomware the moment it starts encrypting data. System Requirements
Provides increased context for fileless threat detections and improved protection against fileless attack methods. Version 10
ATP uses behavioral analysis and file reputation (via Trellix GTI) to decide how to handle unknown files. A standout feature in the 10.7 release is the Story Graph , which provides a visual representation of how a threat entered and attempted to move through the system.