The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Creating response actions

Prev Next

You can create response actions and map them to specific playbooks. When a threat is detected, only the response actions relevant to the type of threat are presented to the user. This narrows down the options available to the user by excluding irrelevant playbooks.

A response action will be available for a threat if the threat matches the rules defined in the response action, and if the threat has indicators applicable to the response action. The list of response actions that apply to a threat or correlation is displayed in the Fix Now menu or menus at the top of the Correlations Details page or Threat Details page.

For example, if you have rules that look for suspicious MD5 hashes, you can associate these rules with a response action that is mapped to the VirusTotal - Indicator Enrichment playbook. If a threat matches a rule and the response action includes an MD5 indicator, that response action appears in the Fix Now menu. When a user executes the response action, the VirusTotal - Indicator Enrichment playbook is triggered.

Note

Users with the Admin or full Analyst role can create, edit, and delete response actions. All users can execute and view response actions.