The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Import and export detection rules

Prev Next

If you have existing custom detection rules, you can quickly and easily import them into Helix. For example, you might have rules that you use with a particular third party product, or rules specific to your organization's requirements. Being able to import these rules saves you time as you don't have to re-create the rule from scratch, or copy and paste the rule.

Note

You can only import custom detection rules in YAML format.

You can import a single custom detection rule, or a file with multiple rules. Imported rules are validated, and any errors are displayed along with an explanation of what went wrong. Incorrectly formatted rules are not imported into Helix.

To import detection rules:

  1. On the Rules page, click Import Rules.

  2. Click Choose File..., select the file you want to import, and then click Upload File.

    Valid rules are imported into Helix and error messages explain why any rules are invalid. Repeat this step for any other files you want to import.

  3. When you have uploaded all your detection rules, click Close.

To export detection rules:

  • On the Rules page, do one of the following:

    1. To export a single rule, at the end of the row click More Options more-options.png > Export > Export Rule.

    2. To export multiple rules, select the checkbox next to each rule and click Actions > Export > Export Rule.

    Note

    You cannot export Trellix rules.