The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Threat detection using IOC rules

Prev Next

Indicators of Compromise (IOCs) are pieces of forensic data, such as file hashes, IP addresses, or registry keys, that identify potentially malicious activity on a network or system. Trellix provides a continuously updated feed of IOCs from the Dynamic Threat Intelligence (DTI) cloud. You can enhance this protection by creating custom IOC rules in Trellix EDR or Forensics workspace.

Create IOC rules using: