The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing false positive rules

Prev Next

Alerts based on rules that match harmless activity are called false positive alerts. Reviewing false positive alerts can waste valuable Administrator, Senior Analyst, and Investigator time. You can suppress false positive alerts by identifying relevant indicator of compromise (IOC) conditions and specific malware, exploit, or generic alert information. The classification is not permanent and can be removed.