The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Execution Control tab

Prev Next

Use this tab to define additional attribute-based and granular rules for files in your setup.

Based on the type of rules you define, a file is allowed, blocked, or monitored based on attributes provided.

Option definitions

Option

Definition

Add

Opens the Add Execution Control Rule dialog box. Configure these options, as needed.

  • Action — Select one of these options when adding an execution control rule.

    • Based on specified attributes

      • Monitor — Select to define rules to monitor file execution when run with specified attributes.

      • Block — Select to define rules to prevent file execution when run with specified attributes.

      • Allow — Select to define rules to allow file execution when run with specified attributes.

    • Block interactive mode for console-based process — Select to define rules to block interactive mode for console-based processes.

  • Process Name — Specify the process for which to specify the rule.

  • Attributes for the rule — Specify one or more of these attributes to define an attribute-based rule. These fields are available only when you select the Based on specified attributes action.

    • Path — Select the associated checkbox to use path as a context-based attribute for the rule and specify the path for the process. The rule comes into play only when the process is run from the specified path.

    • Command Line Argument — Select the associated checkbox to use command-line argument as a context-based attribute for the rule and specify the argument. The rule comes into play only when the process is run with the specified argument.

    • Parent Process Name — Select the associated checkbox to use parent process as a context-based attribute for the rule and specify the name of the parent process. The rule comes into play only when the process is run by the specified parent process.

    • User Name — Select the associated checkbox to specify user name as a context-based attribute for the rule and enter the user name. The rule comes into play only when the process is run by the specified user.

    • Rule Description — Enter a rule description. Make sure the description is meaningful and aptly describes the rule.

  • OK — Saves the changes made.

  • Cancel — Exits without saving the changes and returns to the Execution Control page.

Edit

Opens the Edit Execution Control Rule dialog box with information for a selected rule. Edit the rule as needed, then click OK.

Remove

Deletes the selected rule.