Helix detection rules enable you to manage the volume and efficacy of alerts you monitor regularly without missing new, emerging, or customer-defined threats. When a rule locates a match (a "hit"), it triggers an alert or a log entry, depending on its configuration. If the detection is covered by an exclusion, the event is ignored.
There are two types of rules in Helix:
Trellix rules: Rules created by Trellix experts that detect a wide range of malicious activity. These rules are created and updated regularly. You can change some Trellix rule settings to customize a rule to meet your needs. If you need to change other rule parameters, you can clone the rule, which creates a new custom rule with a unique identifier.
Custom rules: Rules that you define that detect events specific to your environment and organizational needs.