Trellix-defined containment rules block or log actions that contained applications perform. You can change the block and report settings, but you can't otherwise change or delete these rules.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Adaptive Threat Protection from the Products list in the left pane.
From the Category list in the right pane, select Dynamic Application Containment.
Click the Edit link for an editable policy.
In the Containment Rules section, select Block, Report, or both for the rule.
To select or deselect all rules under Block or Report, click Block All or Report All.
To disable the rule, deselect both Block and Report.
In the Exclusions section, configure executables to exclude from Dynamic Application Containment. Processes in the Exclusions list run normally (not contained).
Click Save.