You can search for indicator rules and conditions using the Endpoint Security (HX) Web UI. You cannot search for them using the CLI.
Prerequisites
Admin, Senior Analyst, or Investigator access
To search for indicator rules and conditions:
Log in to the Endpoint Security (HX) Web UI.
Select Rules from the Configure section of the main menu to access the Rules page.
Select the Indicators tab.
In the Search by name, created by, signature, or condition box, enter one of the following:
Name—the indicator rule name
Created by—the user name or other identification of the source of the indicator rule. Trellix-supplied indicator rules usually have source names that start with "General."
Signature—a value provided by other Trellix products
Condition value—the value of the condition, such as the MD5 hash value or filename
Click the magnifying glass on the right side of the search box or press Enter.
The list of indicator rules on the Indicator tab is filtered for only the indicator rules that match your search criteria.
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace > Maintain custom indicator rules
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace > Maintain custom indicator rules