The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing detection rules

Prev Next

Helix detection rules enable you to manage the volume and efficacy of alerts you monitor regularly without missing new, emerging, or customer-defined threats. When a rule locates a match (a "hit"), it triggers an alert or a log entry, depending on its configuration. If the detection is covered by an exclusion, the event is ignored.

There are two types of rules in Helix:

  • Trellix rules: Rules created by Trellix experts that detect a wide range of malicious activity. These rules are created and updated regularly. You can change some Trellix rule settings to customize a rule to meet your needs. If you need to change other rule parameters, you can clone the rule, which creates a new custom rule with a unique identifier.

  • Custom rules: Rules that you define that detect events specific to your environment and organizational needs.