The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Validate and enforce an Expert Rule on a client system

Prev Next

Once you deploy a new Expert Rule to a client test system, validate that the syntax is correct and that it is working properly before deploying more widely. Validate that the syntax for an Expert Rule is correct and enforce it on a client test system to verify that it is working properly before deploying more widely. Syntax checking is available for Files, Registry, and Processes rule types only.

Note

Exploit Prevention is not supported in the ARM architecture.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the client system as administrator.

Policy changes from ePO - On-prem might overwrite changes that you make to Expert Rules on the client system. Make sure to copy your changes back to the Exploit Prevention policy in the Threat Prevention module in ePO - On-prem.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Threat Prevention on the main Status page.

    Or, from the Action menu, select Settings, then click Threat Prevention on the Settings page.

  3. Click Show Advanced.

  4. Click Exploit Prevention.

  5. In the Signatures section, double-click a user-defined Expert Rule.

  6. In the Expert Rule Checker window, click Check.

    The Check button isn't available for Buffer Overflow, Illegal API Use, or Services rule types.

    If the syntax checker finds any errors:

    1. Review the EndpointSecurityPlatform_errors.log file for information about the syntax error.

    2. In Trellix Endpoint Security (ENS) Client, correct the error.

    3. Click Check.

    The Enforce button enables when the errors are resolved.

  7. Copy any updated Expert Rules to the Exploit Prevention policy in the Threat Prevention module in ePO - On-prem.

  8. Click Enforce to save and enforce the rule or Close to cancel any changes and close the Expert Rule Checker window.

  9. Perform the restricted actions that you have written in the rule.

  10. Navigate back to the Event Log page in ENS.

    You can view the events that are triggered for violating the rule. If intended action is not reported, make sure that you have selected Report check box while creating or enforcing Expert rules.