The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Custom rules

Prev Next

Note

Each time a new file containing custom rules is uploaded, all previous rules are overwritten. For information about custom rule file usage, requirements, and the keywords supported by the Network Security, see the Creating Custom Rule Limitations topic in Uploading custom rules using the Web UI.

Network Security supports the use of custom rules for malware analysis. You can load your own format signature rules, which allow theTrellix appliance or sensor to detect and generate alerts for customer-specific traffic patterns.

Custom rules are written and uploaded as ASCII text files. They can include descriptions of malware families based on textual or binary patterns contained in samples of identified families. Custom rule descriptions consist of a set of strings and a Boolean expression that determines the rule’s logic. For information about creating custom rule limitations, see Uploading custom rules using the Web UI.

The results of the custom rule integration with the appliance or sensor are displayed in the Alerts > Alerts > Alerts page of the Web UI.