The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable execution indicator rule generation from appliance alert

Prev Next

You can enable and disable the generation of Endpoint Security (HX) appliance indicator rules from Network Security, Email Security, File Protect, and Malware Analysis appliance alerts, which include alerts on malware callback traffic and host infections. These indicator rules are also referred to as noisy alert indicator rules.

False positives can result when noisy alert indicator rules are enabled. False positives include commonly visited domains that are not malicious, false positive registry entries, and file MD5 indicator rules. Enable the generation of noisy alert indicator rules if you feel you can manage the possibility of false positives. They are disabled by default.

Prerequisites
  • Admin access