The AMSI module uses YARA rules to detect suspicious script execution. These rules are released as part of the Trellix DTI content package and downloaded to the Endpoint Security controller at regular intervals. You can control how often endpoints poll for and download the latest content in the Rule Updates section. The default update setting is one hour.
To configure rule updates:
Log in to the Endpoint Security Web UI.
From the Admin menu, select Polices.
On the Policies page, select the policy you want.
On the Edit Policy page, in the Categories panel select AMSI.
On the AMSI details panel, in the Rule Updates section, select the duration you want in the Hours, Minutes, and Seconds fields.
Click Save.

In this release, you cannot modify the downloaded content or create new custom rules.
Each YARA rule is a simple JSON-format text file. In this release, each rule is approximately 1 KB. Several hundred rules may be released to the DTI for an initial release. Updates may vary in size.