The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Overview

Prev Next

The Trellix Automated Response feature in Trellix Helix uses playbooks to automate and orchestrate processes, and then presents the results in a single pane of glass. This enables you to automate tasks that are repetitive, eliminate human error, and focus on threat analysis and investigation.

A playbook is a workflow of steps tailored to respond to specific types of threats or circumstances. For example, the Microsoft Azure - Disable Users playbook extracts from threats user-type assets with profiles in Azure Active Directory (AD) that have high risk scores, and then disables those users in Azure AD.

Playbooks depend on devices. Most devices pertain to specific playbooks. The Datastore device is used by all playbooks.

Trellix Helix can automatically trigger playbooks when events that are part of a threat have matching rules. You can also execute response actions to automatically trigger playbooks, or trigger playbooks manually.

You can view and inspect the results for all executed playbooks on the Playbook Activities page, and for individual threats on the Correlations Details and Threat Details pages.

Note

The Automated Response feature is available only for threats (Investigate > Threats).