The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Responding to access point violations

Prev Next

When a system access point is violated, the action depends on how the rule is configured.

If the rule was configured to:

  • Report — Information is recorded in the log file.

  • Block — Access is denied.

Take these steps:

  1. Review the log file to determine which system access points were violated and which rules detected the violations.

  2. Configure the Access Protection rules to allow users access to legitimate items and prevent users from accessing protected items.

Use these scenarios to decide which action to take as a response.

Detection type

Scenarios

Unwanted processes

  • If the rule reported the violation in the log file, but didn't block the violation, select Block for the rule.

  • If the rule blocked the violation, but didn't report the violation in the log file, select Report for the rule.

  • If the rule blocked the violation and reported it in the log file, no action is necessary.

  • If you find an unwanted process that wasn't detected, edit the rule to include it as blocked.

Legitimate processes

  • If the rule reported the violation in the log file, but didn't block the violation, deselect Report for the rule.

  • If the rule blocked the violation and reported it in the log file, edit the rule to exclude the legitimate process from being blocked.