The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

How Expert Rules work

Prev Next

Threat Prevention enforces Expert Rules on the client system the same as any other rule.

The signatures in the Exploit Prevention content provide default protection from Trellix Advanced Research Center. If you need to protect additional resources, you can create custom rules in the Access Protection policy. For even further customization, create Expert Rules in the Exploit Prevention policy.

Note

Exploit Prevention is not supported in the ARM architecture.

Here is the workflow of Expert rules:

  1. An administrator creates the Expert rules and enforces them on the client system or self-managed endpoints.

  2. A user or application tries to access the specific object on which the Expert rules are enforced.

  3. Rules examine and perform one of these actions:

    a) allow access if user identity, access types, and other match values comply with the rule.

    b) block access if user identity, access types, and other match values do not comply with the rule.

  4. Log events in the Event Log page of ENS.

GUID-CBB1E91E-36D2-4E93-B835-97239334F759-low.png