The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Services class type

Prev Next

The Services class type protects Windows Services operations.

Note

Exploit Prevention is not supported in the ARM architecture.

Section

Values

Notes

user_name

Executable

services

Name of the service to protect.

(Required)

The name of the service is in the corresponding registry key under HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.

display_names

Display name of the service.

Required.

This name appears in the Services manager and in the registry value HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<name-of-service>\

directives

services:delete

Deletes a service.

services:create

Creates a service.

services:start

Starts a service.

services:stop

Stops a service.

services:pause

Pauses a service.

services:continue

Continues a service after a pause.

services:startup

Changes the startup mode of a service.

services:profile_enable

Enables a hardware profile.

services:profile_disable

Disables a hardware profile.

services:logon

Changes the logon information of a service.