Trellix rule packs are created and managed by Trellix, and contain groups of rules dedicated to specific types of detection. For example, the Phishing rule pack contains rules that detecting phishing attempts in your environment, and the Windows rule pack contains a suite of rules designed to detect hostile or anomalous behavior in Windows event logs and processes.
Your environment already includes a series of Trellix rule packs. You can enable or disable entire Trellix rule packs at once, or enable or disable individual rules within a Trellix rule pack. However, you cannot add customer rules to a Trellix rule pack, and you cannot remove Trellix rules from a Trellix rule pack.