The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Hyperautomation integrated with Trellix Helix

Prev Next

Security analysts face a large number of alerts from multiple sources. Responding manually to each alert is time-consuming, error-prone, and increases the time it takes to detect and respond to threats in your environment. When Trellix Hyperautomation is integrated with Helix, it allows you to create automated workflows that provide faster response on threat detection. When you reach 70%, 90%, and 100% of your allowed daily quota of workflow executions, the UI displays a warning message. The quota includes all types of executions: manual, scheduled, test runs, sub-workflow, and auto-triggered.

Important

Trellix Hyperautomation is only available to users on Trellix-IAM tenants.

There are three main components of Trellix Hyperautomation in Helix:

  • Edges: Containers that connect with an integrated product which is deployed in a different environment to the one the workflow is running on. To view available Edges, or to create a new Edge, go to Main Menu Helix_MegaMenu.png > Integration Hub > View Hyperautomation Edges.

  • Workflows: Automated actions you can take against threats in your Helix environment. Use the filter bar and drop-down menus to filter the table. To view your workflows, go to Main Menu Helix_MegaMenu.png > Workflows. Click a workflow to open it in the Trellix Hyperautomation UI.

  • Workspace: Logs that are created each time you run a workflow for tracking and auditing purposes. Use the filter bar and drop-down menus to filter the table. To view your workflows, go to Main Menu Helix_MegaMenu.png > Workspace. Click a workspace to view it in the Trellix Hyperautomation UI.