You can create Expert rules directly on a client system or self-managed endpoints that aren't managed by ePO.
Note
Exploit Prevention is not supported in the ARM architecture.
Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.
Launch the Trellix Endpoint Security (ENS) Client.
Click Threat Prevention on the main Status page.
Or, from the Action menu ✓, select Settings, then click Threat Prevention on the Settings page.
Click Show Advanced.
In the Signatures section:
Create a rule — Click Add Expert Rule.
Edit an existing user-defined rule — Double-click the rule in the table.
In the Expert Rule Checker page, complete the fields.
Trellix ENS assigns the ID number automatically starting with 20000.
Select the severity and action for the rule.
The severity provides information only; it has no effect on the rule action.
Select Services in the Rule Type drop-down list.
Add the rule code to the Rule content field.
Save the rule, then save the settings.
Validate the new Expert Rule on the client system.