The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Create Expert Rules to protect registry using ePO

Prev Next

Expert rule protects a specific registry by preventing users/unauthorized applications from accessing and modifying the registry keys or values in the registry. Based on the access permission you set in the rule, it blocks and triggers an event, if any unauthorized source access the protected registry.

Task
  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.

  2. From the Category list in the right pane, select Exploit Prevention.

  3. Click the Edit link for an editable policy.

  4. Click Show Advanced.

  5. In the Signatures section, click Add Expert Rule.

  6. In the Expert Rules Properties page, complete the fields.

    Trellix ENS assigns the ID number for the rule automatically starting with 20000.

    1. In the Rule Name, provide a unique name for the Expert rule.

    2. Select Block and Report actions for the rule by selecting the corresponding check boxes.

      Trellix recommends selecting Report action for initial validation. You can select Block and Report check boxes after validating that the rule triggers the appropriate events.

    3. Select the Severity level according to the Expert rule.

      The severity provides information only; it has no effect on the rule action.

    4. Select the Use Expert Rule template checkbox. This populates a template rule in the Rule content box based on the Rule type you select.

      To get a blank template for writing the Expert rules, deselect Use Expert Rule template.

    5. Select Registry in the Rule type drop-down list.

  7. Save the rule, then save the settings.

  8. Validate the new policy on a client system.

  9. Enforce the policy on the client systems.