The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alerting on account usage and system access

Prev Next

It is not uncommon for an attacker to return to a compromised environment throughout the course of an investigation (for example, while the security team is preparing the remediation event). During this time, it may be desirable to setup alerting rules for the use of compromised accounts, logons to or from compromised systems, or logons originating from attacker infrastructure.

See the “Alerting Rules” section for information on how to configure Logon Tracker to produce Endpoint alerts.