Reviewing false positive rules

Prev Next

You can review all of the false positive rules identified in your Trellix Endpoint Security (HX) environment using the Endpoint Security (HX) Web UI. You cannot review them using the CLI.

False positive rules can be individual indicator of compromise (IOC) conditions, specific malware alert information, or exploit alert information identified as false positive.

Prerequisites
  • Admin, Senior Analyst, or Investigator access