The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Reviewing false positive rules

Prev Next

You can review all of the false positive rules identified in your Trellix Endpoint Security (HX) environment using the Endpoint Security (HX) Web UI. You cannot review them using the CLI.

False positive rules can be individual indicator of compromise (IOC) conditions, specific malware alert information, or exploit alert information identified as false positive.

Prerequisites
  • Admin, Senior Analyst, or Investigator access