The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

iUser command

Prev Next

The iUser command returns information about users on a system.

Note

Exploit Prevention is not supported in the ARM architecture.

Syntax

iUser param
                     
                  

Parameters

Parameter

Returns

username

"1" if the user exists on the system, otherwise "0".

list

List of all users on the system.

groups username

List of the groups a user belongs to.

For more Expert Rules examples, visit the Trellix Github repository.