The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Types of Access Protection rules

Prev Next

Use default Access Protection rules or create custom rules to protect your system's access points.

Default Trellix-defined rules are always applied before any user-defined rules.

Rule type

Description

You can...

You can't...

Trellix-defined rules

These rules prevent change to commonly used files and settings.

When the content file is updated, the signatures are updated if needed.

  • Enable and disable these rules.

  • Change the block and report settings for these rules.

  • Add excluded and included executables to these rules.

  • Delete these rules.

  • Change the files and settings protected by these rules.

  • Add subrules or user names to these rules.

User-defined rules

These rules supplement the protection provided by Trellix-defined rules.

  • An empty Executables table indicates that the rule applies to all executables.

  • An empty User Names table indicates that the rule applies to all users.

  • Enable and disable these rules.

  • Change the block and report settings for these rules.

  • Add and delete these rules.

  • Change the configuration of these rules.

Important

Registry READ operations are very expensive in terms of system resources and performance. These rules should only be used in emergency situations due to the expected performance issues that can occur and are not intended for general use.

Exclusions

At the rule level, exclusions and inclusions apply to the specified rule. Otherwise, exclusions apply to all rules. Exclusions are optional.

Example rule to protect a process

Create an Access Protection rule to prevent the Command Prompt (cmd.exe) from being used to run PowerShell (powershell.exe):

  1. Add the cmd.exe executable to the rule.

  2. Add a subrule and select:

    • Processes subrule type

    • Run operation

  3. Add a subrule target executable and specify "powershell.exe" as the file name.