The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Adding and modifying response actions

Prev Next

Select Response > Response Actions to open the Response Actions page. To add a response action, click Add. To edit a response action, click the response action name or select Edit from the menu at the end of the row.

The dialog box that opens contains three sections:

  • General. Name and describe the response action, associate a playbook with it, and select a theme of red or gray. The theme determines which Fix Now menu will include the response action. Critical response actions typically have the red theme, and routine response actions typically have the gray theme.

  • Associated Rules. Click Add Rules and select the rule or rules that trigger the playbook when an event matches the rule.

  • Artifacts Required. View the artifacts relevant to the playbook that is mapped to the response action. This section shows the artifact name, input type (such as string), whether the artifact is mandatory, and whether it is a list.

The following shows an example response action.

HelixXDR_ResponseActionExample.png