The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

iUser command

Prev Next

The iUser command returns information about users on a system.

Note

Exploit Prevention is not supported in the ARM architecture.

Syntax

iUser param
                     
                  

Parameters

Parameter

Returns

username

"1" if the user exists on the system, otherwise "0".

list

List of all users on the system.

groups username

List of the groups a user belongs to.

For more Expert Rules examples, visit the Trellix Github repository.