If tuning requires that additional logic must be added to a Trellix rule, you must clone the rule so its TQL can be edited. Note that this means that any subsequent updates to the original rule by Trellix will not be propagated to the custom rule. This option is also unavailable for any Trellix rule with protected syntax.
For example, the WINDOWS METHODOLOGY [Group Add - Domains Admins] rule triggers on any addition to the Windows Domain Admins group. An organization may want to alert on this, but exclude additions made from certain authorized users.
To clone a rule:
Copy the TQL query using one of the following methods.
On the alert details page under the Helix Enterprise Rule section, click the copy to Clipboard icon.
From the Rules page, highlight the query, right-click, and select Copy.
Create a new rule using the copied query as your starting point.
For more information, see Creating customer rules.