The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Alerting on account usage and system access

Prev Next

It is not uncommon for an attacker to return to a compromised environment throughout the course of an investigation (for example, while the security team is preparing the remediation event). During this time, it may be desirable to setup alerting rules for the use of compromised accounts, logons to or from compromised systems, or logons originating from attacker infrastructure.

See the “Alerting Rules” section for information on how to configure Logon Tracker to produce Endpoint alerts.