The Endpoint Security (HX) software uses intelligence from a variety of sources to monitor endpoint activity. Intelligence (Intel) is used to identify suspicious behavior on your network. Intelligence information is defined in rules.
Rules can be indicator of compromise rules (also known as IOC rules or indicators), Exploit Guard rules, or false positive rules.
Rules consist of one or more conditions. A condition is a specific activity on a host. Examples of a condition include:
A registry key update
A file modification
A DNS lookup
A user account modification
A rule is a collection of conditions that, when combined, identify a specific threat to an endpoint. When rules are triggered, they generate alerts.
Because rules are identified by operating system platform and agent version, Trellix Endpoint Security (HX) Agents on your endpoints can efficiently download rules that are appropriate for the endpoint operating system and agent version.
You can manage indicator and false positive rules using the Endpoint Security (HX) Web UI, but you cannot manage them using the CLI. In addition, Exploit Guard rules are provided and maintained by Trellix only. For information on managing indicator rules, see Managing IOC rules . For information on managing false positive rules, see Managing false positive rules .