The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Services class type

Prev Next

The Services class type protects Windows Services operations.

Note

Exploit Prevention is not supported in the ARM architecture.

Section

Values

Notes

user_name

Executable

services

Name of the service to protect.

(Required)

The name of the service is in the corresponding registry key under HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.

display_names

Display name of the service.

Required.

This name appears in the Services manager and in the registry value HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<name-of-service>\

directives

services:delete

Deletes a service.

services:create

Creates a service.

services:start

Starts a service.

services:stop

Stops a service.

services:pause

Pauses a service.

services:continue

Continues a service after a pause.

services:startup

Changes the startup mode of a service.

services:profile_enable

Enables a hardware profile.

services:profile_disable

Disables a hardware profile.

services:logon

Changes the logon information of a service.