Overview
Agentic Threat Prevention automatically applies controls to hosts to reduce the attack surface and help prevent threats before they impact your environment. For more information, see What is Agentic Threat Prevention?.
For each threat category, define the automatic action: Block or Monitor and how each action is tracked. These threat categories represent different stages of the attack lifecycle, such as lateral movement or command and control. You can view the enforced rules and the threats they prevent.
Prerequisites
TLS is enabled
Configuring Agentic Threat Prevention
By default, Agentic Threat Prevention is enabled. For each Threat Category, the Action is set to Block, and the tracking is set to create an event. To meet your security requirements, change these configurations.
.png?sv=2026-02-06&spr=https&st=2026-08-02T19%3A18%3A36Z&se=2026-08-02T19%3A30%3A36Z&sr=c&sp=r&sig=jcQm3ZLRcVH%2ByrVMipeNztMAgfreKhVipTv9I9idg7k%3D)
To configure Agentic Threat Prevention:
From the navigation menu, click Security > Agentic Threat Prevention.
(Optional) For each Threat Category, configure the Action and tracking options. For more information, see Monitoring Agentic Threat Prevention.
Enable the toggle.
Click Save.
Monitoring Agentic Threat Prevention
You can monitor Agentic Threat Prevention activity with:
The Agentic Threats Page: View details of the controls applied to hosts and the threats prevented from the Agentic Threats page. For more information, see Monitoring Agentic Threat Prevention.
Events: Agentic Threat Prevention generates the following event types:
Control Applied: Generated when a control is applied to a host
Malicious Action Detected (optional): Generated when a malicious action is detected
Configure whether to generate an Event, Notification, or both. If you have an XOps license, an XOps story is also generated
Note: Agentic Threat Prevention Events have the subtype Dynamic Prevention. They can be viewed on the Events page with the Dynamic Prevention preset. For more information, see Analyzing Events in Your Network.
To enable Events or Notifications:
From the navigation menu, click Security > Agentic Threat Prevention.
For each Threat Category, click Event.
Configure the required tracking options:
Subscription Group (For more information, see Creating Subscription Groups)
Mailing List (For more information, see Working with Mailing Lists)
Webhook (For more information, see Sending CMA Notifications via Webhooks)
Click Save.
Excluding Hosts From Controls
To prevent specific controls from being applied to a host, add the relevant signature to the IPS Policy Allowlist. For more information, see Allowlisting IPS Signatures.
You can allowlist either:
Suspicious behavior signatures: No controls associated with the suspicious behavior are applied to the host
Control signatures: Only the selected control is excluded from the host
Identifying Signatures for the IPS Policy Allowlist
Identify both suspicious behavior and control signatures from the Threat Catalog. For more information, see Using the Threat Catalog.
Identifying Suspicious Behavior Signatures
Suspicious behavior signatures describe behaviors detected by the Agentic Threat Prevention engine. Opening a signature shows a description of the behavior and the controls that are applied when the behavior is detected.
.png?sv=2026-02-06&spr=https&st=2026-08-02T19%3A18%3A36Z&se=2026-08-02T19%3A30%3A36Z&sr=c&sp=r&sig=jcQm3ZLRcVH%2ByrVMipeNztMAgfreKhVipTv9I9idg7k%3D)
To identify Suspicious Behavior signatures:
From the navigation menu, click Resources > Threat Catalog.
In the Engine filter, add a filter for Dynamic Prevention.
In the Signature filter, enter cid_atp_c.
The suspicious behavior signatures are displayed.
Identifying Control Signatures
Control signatures represent the individual controls that can be applied when suspicious behavior is detected. Opening a control signature shows a description of the control.
.png?sv=2026-02-06&spr=https&st=2026-08-02T19%3A18%3A36Z&se=2026-08-02T19%3A30%3A36Z&sr=c&sp=r&sig=jcQm3ZLRcVH%2ByrVMipeNztMAgfreKhVipTv9I9idg7k%3D)
To identify Control signatures:
From the navigation menu, click Resources > Threat Catalog.
In the Engine filter, add a filter for Dynamic Prevention.
In the Signature filter, enter cid_atp_r.
The control signatures are displayed.
Excluding Hosts from the Events Page
.png?sv=2026-02-06&spr=https&st=2026-08-02T19%3A18%3A36Z&se=2026-08-02T19%3A30%3A36Z&sr=c&sp=r&sig=jcQm3ZLRcVH%2ByrVMipeNztMAgfreKhVipTv9I9idg7k%3D)
Add suspicious behavior or control signatures to the IPS Policy Allowlist directly from the Events page.
Click the Signature ID link to open a panel with a pre-populated IPS Policy allowlist rule. Review or edit the rule as needed, and then click Apply to add it to the allowlist.